This is the second in a series of demos I am creating about Remote Command Injection vulnerabilities for my paper on them.
This demos POST injections via simply tampering with the parameters/form input and shows the execution of several shell commands on the vulnerable server.
Check out our whitepaper on this HERE: http://insecurety.net/papers/web-apps...
This demo used Mutillidae.
On this page of the site you can watch the video online HTTP POST PHP Command Injection Demo 1 with a duration of hours minute second in good quality, which was uploaded by the user Darren Martyn 15 March 2012, share the link with friends and acquaintances, this video has already been watched 9,750 times on youtube and it was liked by 13 viewers. Enjoy your viewing!