cmdi-command-injection
Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.
Security Assessment
Detected risks:
About cmdi-command-injection
A command injection playbook for security testing, applicable when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks. It opens with first-pass payload families organized by context, covering generic separators, quoted arguments, blind timing, command substitution, and out-of-band DNS, so a tester can quickly pick a starting payload and a backup.
The reference enumerates shell metacharacters and their behavior, including separators like semicolon and ampersand, pipes, conditional operators, command substitution via dollar-parentheses and backticks, redirects, and URL-encoded newlines. It then catalogs vulnerable code patterns across PHP, Python, Node.js, Perl, and Classic ASP, calling out sinks such as shell_exec, subprocess with the shell flag enabled, and child_process exec. For cases with no visible output, it details blind detection through time delays and out-of-band exfiltration over DNS, HTTP, or a web-accessible file.
Additional sections provide a payload library spanning information gathering and both Linux and Windows reverse shells, injection-context variations for quoted, single-quoted, backtick, and file-path contexts, and filter-bypass techniques including space alternatives such as IFS and brace expansion, slash alternatives, keyword assembly from variables, and newline injection. A list of common entry points, from network tools and file conversion to log viewing and archive processing, plus a blind-injection decision tree, helps locate and confirm findings. It is presented as a neutral, factual offensive-security testing resource.
FAQ
When should this playbook be used?
When user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks during a security assessment.
How does it detect blind injection with no visible output?
Through time-based detection using deliberate delays, and out-of-band techniques via DNS lookups, HTTP callbacks, or writing output to a web-accessible file.
Which languages' vulnerable patterns are covered?
PHP, Python, Node.js, Perl, and Classic ASP, with example sinks such as shell_exec, subprocess with the shell flag, os.system, and child_process exec.
Does it include filter-bypass techniques?
Yes. It covers space alternatives like IFS and brace expansion, slash alternatives, keyword assembly from variables, and newline injection.
What shell metacharacters does it enumerate?
Separators and operators such as semicolon, pipe, conditional AND and OR, ampersand, command substitution via dollar-parentheses and backticks, redirects, and URL-encoded newlines.
Install cmdi-command-injection
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills