Critical severity Attack Technique

Command Injection

Shell metacharacters in user input reach an OS command, giving direct code execution.

Overview

Any feature that shells out, including backup, image resizing, PDF conversion and ping diagnostics, becomes an execution primitive if input is concatenated.\nA payload as short as ; whoami is often enough.\nNever build a shell string: use argument arrays, drop to a safe library call, and validate against a strict allow list.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Shell metacharacters reflected in process output
  • Ping or lookup features accepting arbitrary hosts
  • Slow responses when input contains sleep or ping flags

Controls that stop it

  • Validate and Constrain All Input

    Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used