killchain-compendium/exploit/web/php/command_injection.md

11 lines
279 B
Markdown

# PHP Command Injection
Injecting commands to execute code on the server side via php.
## Blind Command Injection
Attacker does not register a direct response.
### Detect Blind Command Injection
Try to save output to URI resource like `output.php`
## Active Command Injection