Command and code injection
Someone tries to run their own commands on your server.
What it is
Shell commands or program code sent as input, hoping the server runs it.
- ; cat /etc/passwd after a file name
- PHP code in an upload's name
- A crafted object that runs code when the site reads it
Why it matters
When it works, the attacker controls the server and everything on it.
When it stops a real visitor
This can catch real text about programming, or a tool of yours that sends commands on purpose. Mark the request as real and that one field is let through.
What you will see most
- The request contained shell commands.
- The input included commands for the server's command line.
- The request contained PHP code.
- The input included the opening tag of a PHP program.
All 45 rules in this kind, as the rule set names them
For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.
- 932120Remote Command Execution: Windows PowerShell Command Found
- 932125Remote Command Execution: Windows Powershell Alias Command Injection
- 932130Remote Command Execution: Unix Shell Expression Found
- 932140Remote Command Execution: Windows FOR/IF Command Found
- 932160Remote Command Execution: Unix Shell Code Found
- 932170Remote Command Execution: Shellshock (CVE-2014-6271)
- 932171Remote Command Execution: Shellshock (CVE-2014-6271)
- 932175Remote Command Execution: Unix shell alias invocation
- 932180Restricted File Upload Attempt
- 932230Remote Command Execution: Unix Command Injection (2-3 chars)
- 932235Remote Command Execution: Unix Command Injection (command without evasion)
- 932250Remote Command Execution: Direct Unix Command Execution
- 932260Remote Command Execution: Direct Unix Command Execution
- 932270Remote Command Execution: Unix Shell Expression Found
- 932280Remote Command Execution: Brace Expansion Found
- 932330Remote Command Execution: Unix shell history invocation
- 932340Remote Command Execution: Direct Unix Command Execution (No Arguments)
- 932370Remote Command Execution: Windows Command Injection
- 932380Remote Command Execution: Windows Command Injection
- 933100PHP Injection Attack: PHP Open Tag Found
- 933110PHP Injection Attack: PHP Script File Upload Found
- 933120PHP Injection Attack: Configuration Directive Found
- 933130PHP Injection Attack: Variables Found
- 933135PHP Injection Attack: Variable Access Found
- 933140PHP Injection Attack: I/O Stream Found
- 933150PHP Injection Attack: High-Risk PHP Function Name Found
- 933160PHP Injection Attack: High-Risk PHP Function Call Found
- 933170PHP Injection Attack: Serialized Object Injection
- 933180PHP Injection Attack: Variable Function Call Found
- 933200PHP Injection Attack: Wrapper scheme detected
- 933210PHP Injection Attack: Variable Function Call Found
- 933220PHP Injection Attack: PHP Session File Upload Attempt
- 934100Node.js Injection Attack 1/2
- 934110Possible Server Side Request Forgery (SSRF) Attack: Cloud provider metadata URL in Parameter
- 934130JavaScript Prototype Pollution
- 934150Ruby Injection Attack
- 934160Node.js DoS attack
- 934170PHP data scheme attack
- 934190Possible Server Side Request Forgery (SSRF) Attack: Scheme-less localhost or internal hostname detected
- 944011Remote Command Execution: Suspicious Java class detected
- 944110Remote Command Execution: Java process spawn (CVE-2017-9805)
- 944120Remote Command Execution: Java serialization (CVE-2015-4852)
- 944130Suspicious Java class detected
- 944140Java Injection Attack: Java Script File Upload Found
- 944150Potential Remote Command Execution: Log4j / Log4shell