Mutillidae — Lab 16 — Web Shell with Command injection

This lab can be found via Labs > Command Injection > Lab 16 — Web Shell with Command injection

Let’s go ahead and create a simple PHP web shell

Now we will upload it to the server

Navigating to the file, and appending uname to the end, doesn’t seem to work

So, we will need to create a different version, with the command we want to execute, built into the shell

Answer: linux

