What is command injection?¶
Command injection makes an application pass attacker-controlled input to an operating-system command. Command-like text in a request is evidence of method or attempt, not proof that the server executed it.
Link input to a server process¶
Preserve the exact request, web and application logs, parent and child processes, command line, service account or cloud role, files, configuration, network connections and returned output.
The application may reject or escape the input. Successful execution is strongest where process telemetry or a resulting effect matches the submitted command; an application error alone is insufficient.
Define the privilege and result¶
Commands often run under a constrained web service, container identity or role. Establish that security context before describing server or network control.
Returned output can support execution but should be tied to the correct host and session. For blind injection, files, processes and outbound traffic may provide the better evidence. Report attempt, successful command and resulting access separately.
Key takeaway
Prove command injection by connecting malicious input to a server-side process and effect, including the actual privilege under which it ran.