# OS Command injection(shell injection) [TOC]   資料來源 : https://portswigger.net/web-security/os-command-injection ## APPRENTICE ### Lab: OS command injection, simple case --2023/05/03 啊題目要我們取得 whoami  隨便挑一個網頁用 burpsuite 抓 request,在 productId 跟 storeId 之間插入 whoami,但是好像沒效ㄟ  將 ```&whoami```反白後,按下 Ctrl+U 將他轉成 URL,送出就成功了  學廢了,學廢了,web 遇到任何 request 問題先轉 URL 再說  #### p.s. 其實應該是要 ```storeId=1|whoami``` 這樣啦,就會出現 username 了,哈哈 
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up