<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Labs Research</title>
    <link>https://www.obrela.com/resources/labs</link>
    <description>Access Labs research material and learn more about the latest attacks in the industry and how to protect your business.</description>
    <language>en</language>
    <pubDate>Thu, 09 Jul 2026 13:49:16 GMT</pubDate>
    <dc:date>2026-07-09T13:49:16Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Kentico CMS 5.5 R2 Critical Vulnerability</title>
      <link>https://www.obrela.com/resources/labs/kentico-cms-5-5-r2-critical-vulnerability</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/kentico-cms-5-5-r2-critical-vulnerability?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract8-Jun-26-2026-10-11-38-6336-AM.png" alt="Kentico CMS 5.5 R2 Critical Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;&lt;strong&gt;Anastasios Stasinopoulos from&amp;nbsp;&lt;a href="https://www.obrela.com/resources/labs-insights/?hsLang=en"&gt;Obrela LABS&lt;/a&gt;&amp;nbsp;team discovered a critical risk vulnerability that affects Kentico CMS, a popular ASP.NET web content management system that is used to build websites, online stores and Web 2.0 community sites.&lt;/strong&gt;&lt;/p&gt; 
 &lt;p&gt;More specifically, Kentico CMS 5.5 R2 build 5.5.3996 was found vulnerable to SQL injection attacks on a specific parameter, allowing a potential attacker – without requiring authentication – to interact with the backend Microsoft SQL server database.&lt;/p&gt; 
 &lt;p&gt;Successful exploitation of this vulnerability allows unauthorized access/modification/deletion of the stored data in the backend database and if specific conditions are met can be also leveraged to complete compromise of the underlying operating system that hosts Kentico.&lt;/p&gt; 
 &lt;p&gt;The software vendor has been informed by Obrela LABS prior to public disclosure of the vulnerability which was registered afterwards with a CVE record:&amp;nbsp;&lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2021-27581"&gt;CVE-2021-27581&lt;/a&gt;&amp;nbsp;.&lt;/p&gt; 
 &lt;p&gt;According to software vendor response it is advised to update Kentico CMS to the latest version that is not vulnerable to this security flaw.&lt;/p&gt; 
 &lt;p&gt;The vulnerability was exploited using the&amp;nbsp;&lt;a href="https://sqlmap.org/"&gt;sqlmap&lt;/a&gt;&amp;nbsp;tool:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Vulnerable parameter: tagname&lt;/li&gt; 
  &lt;li&gt;Type: time-based blind sql injection&lt;/li&gt; 
  &lt;li&gt;Sample payload: tagname=test’+(SELECT CHAR(118)+CHAR(103)+CHAR(85)+CHAR(89) WHERE 1718=1718 AND 6176=(SELECT COUNT(*) FROM sysusers AS sys1,sysusers AS sys2,sysusers AS sys3,sysusers AS sys4,sysusers AS sys5,sysusers AS sys6,sysusers AS sys7))+’&amp;amp;groupid=1&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;&lt;strong&gt;Discovery and public disclosure timeline&lt;/strong&gt;&lt;/p&gt; 
 &lt;div&gt; 
  &lt;ul&gt; 
   &lt;li&gt;2021-02-22 – Discovery&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – Vendor Contact&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – Vendor Triaged Vulnerability&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – MITRE Assigned CVE&lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/kentico-cms-5-5-r2-critical-vulnerability?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract8-Jun-26-2026-10-11-38-6336-AM.png" alt="Kentico CMS 5.5 R2 Critical Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;&lt;strong&gt;Anastasios Stasinopoulos from&amp;nbsp;&lt;a href="https://www.obrela.com/resources/labs-insights/?hsLang=en"&gt;Obrela LABS&lt;/a&gt;&amp;nbsp;team discovered a critical risk vulnerability that affects Kentico CMS, a popular ASP.NET web content management system that is used to build websites, online stores and Web 2.0 community sites.&lt;/strong&gt;&lt;/p&gt; 
 &lt;p&gt;More specifically, Kentico CMS 5.5 R2 build 5.5.3996 was found vulnerable to SQL injection attacks on a specific parameter, allowing a potential attacker – without requiring authentication – to interact with the backend Microsoft SQL server database.&lt;/p&gt; 
 &lt;p&gt;Successful exploitation of this vulnerability allows unauthorized access/modification/deletion of the stored data in the backend database and if specific conditions are met can be also leveraged to complete compromise of the underlying operating system that hosts Kentico.&lt;/p&gt; 
 &lt;p&gt;The software vendor has been informed by Obrela LABS prior to public disclosure of the vulnerability which was registered afterwards with a CVE record:&amp;nbsp;&lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2021-27581"&gt;CVE-2021-27581&lt;/a&gt;&amp;nbsp;.&lt;/p&gt; 
 &lt;p&gt;According to software vendor response it is advised to update Kentico CMS to the latest version that is not vulnerable to this security flaw.&lt;/p&gt; 
 &lt;p&gt;The vulnerability was exploited using the&amp;nbsp;&lt;a href="https://sqlmap.org/"&gt;sqlmap&lt;/a&gt;&amp;nbsp;tool:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Vulnerable parameter: tagname&lt;/li&gt; 
  &lt;li&gt;Type: time-based blind sql injection&lt;/li&gt; 
  &lt;li&gt;Sample payload: tagname=test’+(SELECT CHAR(118)+CHAR(103)+CHAR(85)+CHAR(89) WHERE 1718=1718 AND 6176=(SELECT COUNT(*) FROM sysusers AS sys1,sysusers AS sys2,sysusers AS sys3,sysusers AS sys4,sysusers AS sys5,sysusers AS sys6,sysusers AS sys7))+’&amp;amp;groupid=1&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;&lt;strong&gt;Discovery and public disclosure timeline&lt;/strong&gt;&lt;/p&gt; 
 &lt;div&gt; 
  &lt;ul&gt; 
   &lt;li&gt;2021-02-22 – Discovery&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – Vendor Contact&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – Vendor Triaged Vulnerability&lt;/li&gt; 
   &lt;li&gt;2021-02-23 – MITRE Assigned CVE&lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fkentico-cms-5-5-r2-critical-vulnerability&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 08 Mar 2021 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/kentico-cms-5-5-r2-critical-vulnerability</guid>
      <dc:date>2021-03-08T00:00:00Z</dc:date>
      <dc:creator>The Obrela LABS Team</dc:creator>
    </item>
    <item>
      <title>Client Side Penetration Testing – T&amp;T Part 1</title>
      <link>https://www.obrela.com/resources/labs/client-side-penetration-testing-tt-part-1</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/client-side-penetration-testing-tt-part-1?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_City8-Jun-26-2026-10-11-37-5752-AM.png" alt="Client Side Penetration Testing – T&amp;amp;T Part 1" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;Most client-side attacks are based on delivering emails to the target, nevertheless by underestimating the need to build an adequate “trust level” towards the target, there’s a fair chance that the exercise will fail even at this early state. Below we will begin by listing some techniques, considerations, and tips on how to successfully deliver emails and establish this “trust level”.&lt;/p&gt; 
 &lt;h2&gt;SMTP in general&lt;/h2&gt; 
 &lt;p&gt;SMTP servers which are flagged as the MX for each domain, by design, accept connections by any system on the internet and relay the messages to their users. The term “system” does not imply mail servers, so the “system” does not have to be a mail server necessarily. Anyone may connect to this type of SMTP server at port 25 using a client (Outlook, Thunderbird or even telnet) and send a message directly to its domain(s) users. Unless this SMTP server is an open relay (very rare nowadays) messages can be relayed only to users of the domain(s) it serves, any other attempt to send messages to other domains will be rejected.&lt;/p&gt; 
 &lt;h2&gt;&lt;strong&gt;MX enumeration&lt;/strong&gt;&lt;/h2&gt; 
 &lt;p&gt;As a first step the target’s MX server that is responsible for email relaying, has to be identified. This can be done easily by querying any DNS server for the target’s MX records:&lt;/p&gt; 
 &lt;div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ host -t mx target.com
&lt;p&gt;target.com mail is handled by 20 mx2.target.com.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;target.com mail is handled by 10 mx1.target.com.&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;h2&gt;&lt;strong&gt;Mail spoofing techniques&lt;/strong&gt;&lt;/h2&gt; 
  &lt;p&gt;Obviously, the chances that an email will seem legitimate are increased dramatically if the sender email address is spoofed to an email address which belongs to the target’s domain. The sender address is declared in two fields.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;ul&gt; 
  &lt;li&gt;The “MAIL FROM” SMTP command that is in fact used as “Bounce To” address in order to reach the sender in case of delivery failure&lt;/li&gt; 
  &lt;li&gt;The message header “From: “ (e.g. From: “Spoofed”  ) that defines the address that will shown as sender at target’s mail client &lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;During usual email communication using clients like Outlook, Thunderbird, etc. the user cannot control these fields directly. Both are filled by the mail client with the email address that was defined upon user account creation.&lt;/p&gt; 
 &lt;p&gt;&lt;em&gt;&lt;strong&gt;MAIL FROM command&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;Below we describe how to detect errors and blocking mechanisms when using the MAIL FROM command in order to spoof the target’s email. Telnet or a similar program should be used in order to quickly and correctly identify such mechanisms. After target enumeration, the actual spoofed emails can be sent by any email client properly configured to send email directly to target’s MX server.&lt;/p&gt; 
 &lt;p&gt;Since there are several mechanisms that will block the spoofed “MAIL FROM”, the most important part is to check if the email has reached the target.&lt;/p&gt; 
 &lt;p&gt;The message can be relayed from any SMTP server to reach the target’s MX. The reason we choose directly the target’s MX to communicate with, is that we will have strong indications if our message is rejected (due to blocking technologies that are mentioned below) through error messages that would not otherwise be visible (if an intermediate SMTP was used to relay the message).&lt;/p&gt; 
 &lt;p&gt;An example SMTP communication with target’s MX server with telnet is demonstrated below.&lt;/p&gt; 
 &lt;div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ telnet mx1.target.com 25
&lt;p&gt;Connected to mx1.target.com.&lt;/p&gt;
&lt;p&gt;Escape character is '^]'.&lt;/p&gt;
&lt;p&gt;220 mx1.target.com ESMTP - Welcome&lt;/p&gt;
&lt;p&gt;HELO test&lt;/p&gt;
&lt;p&gt;250 mx1.target.com says HELO to [xxx.xxx.xxx.xxx:xxxx]&lt;/p&gt;
&lt;p&gt;MAIL FROM: &lt;/p&gt;
&lt;p&gt;250 2.1.0 Ok&lt;/p&gt;
&lt;p&gt;RCPT TO: &lt;/p&gt;
&lt;p&gt;250 2.1.5 Ok&lt;/p&gt;
&lt;p&gt;DATA&lt;/p&gt;
&lt;p&gt;354 continue. finished with "\r\n.\r\n"&lt;/p&gt;
&lt;p&gt;Date: Fri, 1 Aug 2014 11:12:29 +0300&lt;/p&gt;
&lt;p&gt;From: Spoofed &lt;/p&gt;
&lt;p&gt;User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0&lt;/p&gt;
&lt;p&gt;MIME-Version: 1.0&lt;/p&gt;
&lt;p&gt;To: "Target &amp;gt;&amp;gt; Target" &lt;/p&gt;
&lt;p&gt;Subject: Email subject&lt;/p&gt;
&lt;p&gt;Content-Type: text/plain; charset=utf-8; format=flowed&lt;/p&gt;
&lt;p&gt;Content-Transfer-Encoding: 7bit&lt;/p&gt;
 
&lt;p&gt;Email message&lt;/p&gt;
 
&lt;p&gt;.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;250 2.0.0 Ok: queued as XX/XX-XXXXX-XXXXXXXX&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;p&gt;Observe for error responses. Below are some examples of rejected attempts:&lt;/p&gt; 
  &lt;ul&gt; 
   &lt;li&gt;Mail server rejects spoofed sender &lt;pre class="language-undefined"&gt;&lt;code&gt;Error msg: 
      
      &lt;/code&gt;&lt;/pre&gt; &lt;/li&gt; 
   &lt;li&gt;Sender IP blacklisted: &lt;pre class="language-undefined"&gt;&lt;code&gt;Error msg: 554 Client host [xxx.xxx.xx.xx.xx] blocked using spam.target.com=[xx.xx.xx.xx] Spamhaus PBL. Please visit http://www.spamhaus.org/lookup/ for more information on why this message could not be delivered&lt;/code&gt;&lt;/pre&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
 &lt;p&gt;&lt;strong&gt;&lt;em&gt;“From: ” header&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; 
 &lt;p&gt;If the above technique fails due to rejected MAIL FROM from a legitimate served domain email address (MX has no reason to accept messages from the domain users it serves, the latter should be done by another SMTP that uses authentication), then we may possibly trick the MX server with a MAIL FROM from a random email address e.g. me@gmail.com, but forge the “From:” header. Using the “From: “ header in order to spoof the sender addresses when sending an email might fail without producing any errors. Thus, it is proposed only if the previously described technique has failed. Below we demonstrate this technique using a telnet client. We may use command line email clients, which are easier to use, that will accept the data section of an email through a given file.&lt;/p&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;pre class="language-bash"&gt;&lt;code&gt;$ telnet mx1.target.com 25
&lt;p&gt;Connected to mx1.target.com.&lt;/p&gt;
&lt;p&gt;Escape character is '^]'.&lt;/p&gt;
&lt;p&gt;220 mx1.target.com ESMTP - Welcome&lt;/p&gt;
&lt;p&gt;HELO test&lt;/p&gt;
&lt;p&gt;250 mx1.target.com says HELO to [xxx.xxx.xxx.xxx:xxxx]&lt;/p&gt;
&lt;p&gt;MAIL FROM: &lt;/p&gt;
&lt;p&gt;250 2.1.0 Ok&lt;/p&gt;
&lt;p&gt;RCPT TO: &lt;/p&gt;
&lt;p&gt;250 2.1.5 Ok&lt;/p&gt;
&lt;p&gt;DATA&lt;/p&gt;
&lt;p&gt;354 continue. finished with "\r\n.\r\n"&lt;/p&gt;
&lt;p&gt;Date: Fri, 1 Aug 2014 11:12:29 +0300&lt;/p&gt;
&lt;p&gt;From: Spoofed &lt;/p&gt;
&lt;p&gt;User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0&lt;/p&gt;
&lt;p&gt;MIME-Version: 1.0&lt;/p&gt;
&lt;p&gt;To: "Target &amp;gt;&amp;gt; Target" &lt;/p&gt;
&lt;p&gt;Subject: Email subject&lt;/p&gt;
&lt;p&gt;Content-Type: text/plain; charset=utf-8; format=flowed&lt;/p&gt;
&lt;p&gt;Content-Transfer-Encoding: 7bit&lt;/p&gt;
 
&lt;p&gt;Email message&lt;/p&gt;
 
&lt;p&gt;.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;250 2.0.0 Ok: queued as XX/XX-XXXXX-XXXXXXXX&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
   &lt;h2&gt;&lt;strong&gt;Blocking technologies&lt;/strong&gt;&lt;/h2&gt; 
   &lt;p&gt;&lt;strong&gt;&lt;em&gt;Sender Policy Framework (SPF)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; 
   &lt;p&gt;Since SMTP itself does not have a way to verify that the address that is used in MAIL FROM command is the real one, SPF (ref. Wikipedia https://en.wikipedia.org/wiki/Sender_Policy_Framework) fills that gap but only for the MAIL FROM command and not the From header of message. The following demonstrates a domain that advertises SPF:&lt;/p&gt; 
  &lt;/div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ dig +short TXT target.com
&lt;/code&gt;&lt;p&gt;&lt;code&gt;"v=spf1 ip4:XXX.XXX.XXX.X/XX a mx ?all"&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;p&gt;&lt;em&gt;Note: It’s not in scope of this article to fully explain how to correctly setup SPF, but an important thing to remember is that the MX SMTP server must be configured to honor SPF records, even for the domain(s) it serves.&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;&lt;em&gt;&lt;strong&gt;DomainKeys Identified Mail (DKIM)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;As mentioned already, SPF does not verify message content. To overcome this limitation DKIM (ref. Wikipedia https://en.wikipedia.org/wiki/Dkim) is utilized that signs the message to confirm its origin.&lt;/p&gt; 
  &lt;p&gt;&lt;em&gt;&lt;strong&gt;MS Exchange reject spoofed domain emails&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;MS Exchange can be configured to prevent spoofed emails which target authoritative domain(s) by removing the “ms-exch-smtp-accept-authoritative-domain-sender” permission assigned to MX SMTP servers. For further information follow the&amp;nbsp;&lt;a href="https://exchangepedia.com/2008/09/how-to-prevent-annoying-spam-from-your-own-domain.html"&gt;link&lt;/a&gt;&amp;nbsp;(the configuration is still the same for newer versions of MS Exchange, like 2010 and 2013)&lt;/p&gt; 
  &lt;h2&gt;&lt;strong&gt;Tips&lt;/strong&gt;&lt;/h2&gt; 
 &lt;/div&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Mail servers may reject messages from systems without a FQDN.&lt;/li&gt; 
  &lt;li&gt;Messages from dynamic IPs will likely be rejected because there is common practice to include dynamic IP ranges to spam-lists to prevent spam.&lt;/li&gt; 
  &lt;li&gt;Do not attach executables to emails because they will likely blocked&lt;/li&gt; 
  &lt;li&gt;Many mail servers block password protected archives too for obvious reasons&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/client-side-penetration-testing-tt-part-1?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_City8-Jun-26-2026-10-11-37-5752-AM.png" alt="Client Side Penetration Testing – T&amp;amp;T Part 1" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;Most client-side attacks are based on delivering emails to the target, nevertheless by underestimating the need to build an adequate “trust level” towards the target, there’s a fair chance that the exercise will fail even at this early state. Below we will begin by listing some techniques, considerations, and tips on how to successfully deliver emails and establish this “trust level”.&lt;/p&gt; 
 &lt;h2&gt;SMTP in general&lt;/h2&gt; 
 &lt;p&gt;SMTP servers which are flagged as the MX for each domain, by design, accept connections by any system on the internet and relay the messages to their users. The term “system” does not imply mail servers, so the “system” does not have to be a mail server necessarily. Anyone may connect to this type of SMTP server at port 25 using a client (Outlook, Thunderbird or even telnet) and send a message directly to its domain(s) users. Unless this SMTP server is an open relay (very rare nowadays) messages can be relayed only to users of the domain(s) it serves, any other attempt to send messages to other domains will be rejected.&lt;/p&gt; 
 &lt;h2&gt;&lt;strong&gt;MX enumeration&lt;/strong&gt;&lt;/h2&gt; 
 &lt;p&gt;As a first step the target’s MX server that is responsible for email relaying, has to be identified. This can be done easily by querying any DNS server for the target’s MX records:&lt;/p&gt; 
 &lt;div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ host -t mx target.com
&lt;p&gt;target.com mail is handled by 20 mx2.target.com.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;target.com mail is handled by 10 mx1.target.com.&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;h2&gt;&lt;strong&gt;Mail spoofing techniques&lt;/strong&gt;&lt;/h2&gt; 
  &lt;p&gt;Obviously, the chances that an email will seem legitimate are increased dramatically if the sender email address is spoofed to an email address which belongs to the target’s domain. The sender address is declared in two fields.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;ul&gt; 
  &lt;li&gt;The “MAIL FROM” SMTP command that is in fact used as “Bounce To” address in order to reach the sender in case of delivery failure&lt;/li&gt; 
  &lt;li&gt;The message header “From: “ (e.g. From: “Spoofed”  ) that defines the address that will shown as sender at target’s mail client &lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;During usual email communication using clients like Outlook, Thunderbird, etc. the user cannot control these fields directly. Both are filled by the mail client with the email address that was defined upon user account creation.&lt;/p&gt; 
 &lt;p&gt;&lt;em&gt;&lt;strong&gt;MAIL FROM command&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;Below we describe how to detect errors and blocking mechanisms when using the MAIL FROM command in order to spoof the target’s email. Telnet or a similar program should be used in order to quickly and correctly identify such mechanisms. After target enumeration, the actual spoofed emails can be sent by any email client properly configured to send email directly to target’s MX server.&lt;/p&gt; 
 &lt;p&gt;Since there are several mechanisms that will block the spoofed “MAIL FROM”, the most important part is to check if the email has reached the target.&lt;/p&gt; 
 &lt;p&gt;The message can be relayed from any SMTP server to reach the target’s MX. The reason we choose directly the target’s MX to communicate with, is that we will have strong indications if our message is rejected (due to blocking technologies that are mentioned below) through error messages that would not otherwise be visible (if an intermediate SMTP was used to relay the message).&lt;/p&gt; 
 &lt;p&gt;An example SMTP communication with target’s MX server with telnet is demonstrated below.&lt;/p&gt; 
 &lt;div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ telnet mx1.target.com 25
&lt;p&gt;Connected to mx1.target.com.&lt;/p&gt;
&lt;p&gt;Escape character is '^]'.&lt;/p&gt;
&lt;p&gt;220 mx1.target.com ESMTP - Welcome&lt;/p&gt;
&lt;p&gt;HELO test&lt;/p&gt;
&lt;p&gt;250 mx1.target.com says HELO to [xxx.xxx.xxx.xxx:xxxx]&lt;/p&gt;
&lt;p&gt;MAIL FROM: &lt;/p&gt;
&lt;p&gt;250 2.1.0 Ok&lt;/p&gt;
&lt;p&gt;RCPT TO: &lt;/p&gt;
&lt;p&gt;250 2.1.5 Ok&lt;/p&gt;
&lt;p&gt;DATA&lt;/p&gt;
&lt;p&gt;354 continue. finished with "\r\n.\r\n"&lt;/p&gt;
&lt;p&gt;Date: Fri, 1 Aug 2014 11:12:29 +0300&lt;/p&gt;
&lt;p&gt;From: Spoofed &lt;/p&gt;
&lt;p&gt;User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0&lt;/p&gt;
&lt;p&gt;MIME-Version: 1.0&lt;/p&gt;
&lt;p&gt;To: "Target &amp;gt;&amp;gt; Target" &lt;/p&gt;
&lt;p&gt;Subject: Email subject&lt;/p&gt;
&lt;p&gt;Content-Type: text/plain; charset=utf-8; format=flowed&lt;/p&gt;
&lt;p&gt;Content-Transfer-Encoding: 7bit&lt;/p&gt;
 
&lt;p&gt;Email message&lt;/p&gt;
 
&lt;p&gt;.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;250 2.0.0 Ok: queued as XX/XX-XXXXX-XXXXXXXX&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;p&gt;Observe for error responses. Below are some examples of rejected attempts:&lt;/p&gt; 
  &lt;ul&gt; 
   &lt;li&gt;Mail server rejects spoofed sender &lt;pre class="language-undefined"&gt;&lt;code&gt;Error msg: 
      
      &lt;/code&gt;&lt;/pre&gt; &lt;/li&gt; 
   &lt;li&gt;Sender IP blacklisted: &lt;pre class="language-undefined"&gt;&lt;code&gt;Error msg: 554 Client host [xxx.xxx.xx.xx.xx] blocked using spam.target.com=[xx.xx.xx.xx] Spamhaus PBL. Please visit http://www.spamhaus.org/lookup/ for more information on why this message could not be delivered&lt;/code&gt;&lt;/pre&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
 &lt;p&gt;&lt;strong&gt;&lt;em&gt;“From: ” header&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; 
 &lt;p&gt;If the above technique fails due to rejected MAIL FROM from a legitimate served domain email address (MX has no reason to accept messages from the domain users it serves, the latter should be done by another SMTP that uses authentication), then we may possibly trick the MX server with a MAIL FROM from a random email address e.g. me@gmail.com, but forge the “From:” header. Using the “From: “ header in order to spoof the sender addresses when sending an email might fail without producing any errors. Thus, it is proposed only if the previously described technique has failed. Below we demonstrate this technique using a telnet client. We may use command line email clients, which are easier to use, that will accept the data section of an email through a given file.&lt;/p&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;pre class="language-bash"&gt;&lt;code&gt;$ telnet mx1.target.com 25
&lt;p&gt;Connected to mx1.target.com.&lt;/p&gt;
&lt;p&gt;Escape character is '^]'.&lt;/p&gt;
&lt;p&gt;220 mx1.target.com ESMTP - Welcome&lt;/p&gt;
&lt;p&gt;HELO test&lt;/p&gt;
&lt;p&gt;250 mx1.target.com says HELO to [xxx.xxx.xxx.xxx:xxxx]&lt;/p&gt;
&lt;p&gt;MAIL FROM: &lt;/p&gt;
&lt;p&gt;250 2.1.0 Ok&lt;/p&gt;
&lt;p&gt;RCPT TO: &lt;/p&gt;
&lt;p&gt;250 2.1.5 Ok&lt;/p&gt;
&lt;p&gt;DATA&lt;/p&gt;
&lt;p&gt;354 continue. finished with "\r\n.\r\n"&lt;/p&gt;
&lt;p&gt;Date: Fri, 1 Aug 2014 11:12:29 +0300&lt;/p&gt;
&lt;p&gt;From: Spoofed &lt;/p&gt;
&lt;p&gt;User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0&lt;/p&gt;
&lt;p&gt;MIME-Version: 1.0&lt;/p&gt;
&lt;p&gt;To: "Target &amp;gt;&amp;gt; Target" &lt;/p&gt;
&lt;p&gt;Subject: Email subject&lt;/p&gt;
&lt;p&gt;Content-Type: text/plain; charset=utf-8; format=flowed&lt;/p&gt;
&lt;p&gt;Content-Transfer-Encoding: 7bit&lt;/p&gt;
 
&lt;p&gt;Email message&lt;/p&gt;
 
&lt;p&gt;.&lt;/p&gt;
&lt;/code&gt;&lt;p&gt;&lt;code&gt;250 2.0.0 Ok: queued as XX/XX-XXXXX-XXXXXXXX&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
   &lt;h2&gt;&lt;strong&gt;Blocking technologies&lt;/strong&gt;&lt;/h2&gt; 
   &lt;p&gt;&lt;strong&gt;&lt;em&gt;Sender Policy Framework (SPF)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; 
   &lt;p&gt;Since SMTP itself does not have a way to verify that the address that is used in MAIL FROM command is the real one, SPF (ref. Wikipedia https://en.wikipedia.org/wiki/Sender_Policy_Framework) fills that gap but only for the MAIL FROM command and not the From header of message. The following demonstrates a domain that advertises SPF:&lt;/p&gt; 
  &lt;/div&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;$ dig +short TXT target.com
&lt;/code&gt;&lt;p&gt;&lt;code&gt;"v=spf1 ip4:XXX.XXX.XXX.X/XX a mx ?all"&lt;/code&gt;&lt;/p&gt;&lt;/pre&gt; 
  &lt;p&gt;&lt;em&gt;Note: It’s not in scope of this article to fully explain how to correctly setup SPF, but an important thing to remember is that the MX SMTP server must be configured to honor SPF records, even for the domain(s) it serves.&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;&lt;em&gt;&lt;strong&gt;DomainKeys Identified Mail (DKIM)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;As mentioned already, SPF does not verify message content. To overcome this limitation DKIM (ref. Wikipedia https://en.wikipedia.org/wiki/Dkim) is utilized that signs the message to confirm its origin.&lt;/p&gt; 
  &lt;p&gt;&lt;em&gt;&lt;strong&gt;MS Exchange reject spoofed domain emails&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; 
  &lt;p&gt;MS Exchange can be configured to prevent spoofed emails which target authoritative domain(s) by removing the “ms-exch-smtp-accept-authoritative-domain-sender” permission assigned to MX SMTP servers. For further information follow the&amp;nbsp;&lt;a href="https://exchangepedia.com/2008/09/how-to-prevent-annoying-spam-from-your-own-domain.html"&gt;link&lt;/a&gt;&amp;nbsp;(the configuration is still the same for newer versions of MS Exchange, like 2010 and 2013)&lt;/p&gt; 
  &lt;h2&gt;&lt;strong&gt;Tips&lt;/strong&gt;&lt;/h2&gt; 
 &lt;/div&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Mail servers may reject messages from systems without a FQDN.&lt;/li&gt; 
  &lt;li&gt;Messages from dynamic IPs will likely be rejected because there is common practice to include dynamic IP ranges to spam-lists to prevent spam.&lt;/li&gt; 
  &lt;li&gt;Do not attach executables to emails because they will likely blocked&lt;/li&gt; 
  &lt;li&gt;Many mail servers block password protected archives too for obvious reasons&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fclient-side-penetration-testing-tt-part-1&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 12 Feb 2021 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/client-side-penetration-testing-tt-part-1</guid>
      <dc:date>2021-02-12T00:00:00Z</dc:date>
      <dc:creator>No Author</dc:creator>
    </item>
    <item>
      <title>OpenMediaVault Remote Code Execution (RCE) Vulnerability</title>
      <link>https://www.obrela.com/resources/labs/openmediavault-remote-code-execution-rce-vulnerability</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/openmediavault-remote-code-execution-rce-vulnerability?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="OpenMediaVault Remote Code Execution (RCE) Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;h3&gt;&lt;strong&gt;Abstract&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;&lt;i&gt;On this article we will be focused on the identification and exploitation of CVE-2020-26124 [1], a remote code execution (RCE) vulnerability affecting OpenMediaVault [2],on specific versions before 4.1.36 and 5.x before 5.5.12.&lt;/i&gt;&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;OpenMediaVault is a free Linux distribution designed for Network-Attached Storage (NAS) that offers services like SSH, (S)FTP, SMB/CIFS, DAAP media server, RSync, BitTorrent client and many more. OpenMediaVault is based on the Debian operating system, and is licensed under the GNU General Public License v3 while project’s lead developer is Volker Theile, who instituted by the end of 2009.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Vulnerability Details&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Our research began on 2020-09-26, when we initially installed the (latest till then) version 5.5.11-1 of OpenMediaVault, which is freely available for downloading though SourceForge [3], on a virtual machine in our lab. After the successful installation and setup of OpenMediaVault, we logged in to the web-based provisioning GUI, using the default administrative credentials (i.e. username:”admin” and password:“openmediavault”).&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/openmediavault-remote-code-execution-rce-vulnerability?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="OpenMediaVault Remote Code Execution (RCE) Vulnerability" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;h3&gt;&lt;strong&gt;Abstract&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;&lt;i&gt;On this article we will be focused on the identification and exploitation of CVE-2020-26124 [1], a remote code execution (RCE) vulnerability affecting OpenMediaVault [2],on specific versions before 4.1.36 and 5.x before 5.5.12.&lt;/i&gt;&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;OpenMediaVault is a free Linux distribution designed for Network-Attached Storage (NAS) that offers services like SSH, (S)FTP, SMB/CIFS, DAAP media server, RSync, BitTorrent client and many more. OpenMediaVault is based on the Debian operating system, and is licensed under the GNU General Public License v3 while project’s lead developer is Volker Theile, who instituted by the end of 2009.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Vulnerability Details&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Our research began on 2020-09-26, when we initially installed the (latest till then) version 5.5.11-1 of OpenMediaVault, which is freely available for downloading though SourceForge [3], on a virtual machine in our lab. After the successful installation and setup of OpenMediaVault, we logged in to the web-based provisioning GUI, using the default administrative credentials (i.e. username:”admin” and password:“openmediavault”).&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fopenmediavault-remote-code-execution-rce-vulnerability&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 04 Nov 2020 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/openmediavault-remote-code-execution-rce-vulnerability</guid>
      <dc:date>2020-11-04T00:00:00Z</dc:date>
      <dc:creator>Anastasios Stasinopoulous</dc:creator>
    </item>
    <item>
      <title>Trixbox CE RCE Vulnerability Case Study</title>
      <link>https://www.obrela.com/resources/labs/trixbox-ce-rce-vulnerability-case-study</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/trixbox-ce-rce-vulnerability-case-study?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract6-Jun-26-2026-10-11-16-1465-AM.png" alt="Trixbox CE RCE Vulnerability Case Study" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;h3&gt;&lt;b&gt;1. Intro&lt;/b&gt;&lt;/h3&gt; 
 &lt;p&gt;The Asterisk PBX and more specifically the Asterisk web-based provisioning GUI interface often stands as a primary target during a Penetration Test, due to its promising potential in case of compromise.&lt;/p&gt; 
 &lt;p&gt;During this case-study we will be focused on Trixbox CE which is the Community Edition of Trixbox (formerly Asterisk@Home), an easy to install VOIP phone system based on the Asterisk PBX. Trixbox CE is a completely free and open-source software available under a GPLv2 license with over two million downloads as of August 22, 2009.&lt;/p&gt; 
 &lt;p&gt;It is important to note that in October 2012, Fonality announced that they would no longer support and/or update Trixbox CE, and would instead focus on Trixbox Pro, the commercial version of Trixbox.&lt;/p&gt; 
 &lt;h3&gt;&lt;b&gt;2. Trixbox CE 2.8.0.4 Exploitation: From Zero to Herο&lt;/b&gt;&lt;/h3&gt; 
 &lt;h4&gt;&lt;b&gt;2.1 Installation and Lab Setup&lt;/b&gt;&lt;/h4&gt; 
 &lt;p&gt;In order to perform the assessment against Trixbox CE, we installed the latest version of Trixbox CE v2.8.0.4 ISO [1] on a virtual machine, which is available for downloading via SourceForge.&lt;/p&gt; 
 &lt;p&gt;Trixbox CE’s core technologies include:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;The Linux distribution on which Trixbox CE is built (i.e. CentOS).&lt;/li&gt; 
  &lt;li&gt;Asterisk which provides the core PBX functionality.&lt;/li&gt; 
  &lt;li&gt;FreePBX which provides a web-based provisioning GUI interface for managing and configuring Asterisk through a web browser.&lt;/li&gt; 
  &lt;li&gt;Flash Operator Panel (FOP) which provides a graphical overview of current calls and provides controls to operators.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;After the successful installation of the Trixbox CE v2.8.0.4 ISO on a virtual machine on our lab, we logged in to the Trixbox CE web-based provisioning GUI interface, using the default administrative credentials “maint:password”.&lt;/p&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;h4&gt;&lt;b&gt;2.2 Identification and Exploitation of CVE-2020-7351&lt;/b&gt;&lt;/h4&gt; 
 &lt;p&gt;Through the main administrative menu, we navigated to a functionality (“&lt;b&gt;PBX -&amp;gt; End Point Configuration&lt;/b&gt;”) which maps network devices on a user-defined subnet.&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/trixbox-ce-rce-vulnerability-case-study?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract6-Jun-26-2026-10-11-16-1465-AM.png" alt="Trixbox CE RCE Vulnerability Case Study" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;h3&gt;&lt;b&gt;1. Intro&lt;/b&gt;&lt;/h3&gt; 
 &lt;p&gt;The Asterisk PBX and more specifically the Asterisk web-based provisioning GUI interface often stands as a primary target during a Penetration Test, due to its promising potential in case of compromise.&lt;/p&gt; 
 &lt;p&gt;During this case-study we will be focused on Trixbox CE which is the Community Edition of Trixbox (formerly Asterisk@Home), an easy to install VOIP phone system based on the Asterisk PBX. Trixbox CE is a completely free and open-source software available under a GPLv2 license with over two million downloads as of August 22, 2009.&lt;/p&gt; 
 &lt;p&gt;It is important to note that in October 2012, Fonality announced that they would no longer support and/or update Trixbox CE, and would instead focus on Trixbox Pro, the commercial version of Trixbox.&lt;/p&gt; 
 &lt;h3&gt;&lt;b&gt;2. Trixbox CE 2.8.0.4 Exploitation: From Zero to Herο&lt;/b&gt;&lt;/h3&gt; 
 &lt;h4&gt;&lt;b&gt;2.1 Installation and Lab Setup&lt;/b&gt;&lt;/h4&gt; 
 &lt;p&gt;In order to perform the assessment against Trixbox CE, we installed the latest version of Trixbox CE v2.8.0.4 ISO [1] on a virtual machine, which is available for downloading via SourceForge.&lt;/p&gt; 
 &lt;p&gt;Trixbox CE’s core technologies include:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;The Linux distribution on which Trixbox CE is built (i.e. CentOS).&lt;/li&gt; 
  &lt;li&gt;Asterisk which provides the core PBX functionality.&lt;/li&gt; 
  &lt;li&gt;FreePBX which provides a web-based provisioning GUI interface for managing and configuring Asterisk through a web browser.&lt;/li&gt; 
  &lt;li&gt;Flash Operator Panel (FOP) which provides a graphical overview of current calls and provides controls to operators.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;After the successful installation of the Trixbox CE v2.8.0.4 ISO on a virtual machine on our lab, we logged in to the Trixbox CE web-based provisioning GUI interface, using the default administrative credentials “maint:password”.&lt;/p&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;h4&gt;&lt;b&gt;2.2 Identification and Exploitation of CVE-2020-7351&lt;/b&gt;&lt;/h4&gt; 
 &lt;p&gt;Through the main administrative menu, we navigated to a functionality (“&lt;b&gt;PBX -&amp;gt; End Point Configuration&lt;/b&gt;”) which maps network devices on a user-defined subnet.&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Ftrixbox-ce-rce-vulnerability-case-study&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 18 May 2020 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/trixbox-ce-rce-vulnerability-case-study</guid>
      <dc:date>2020-05-18T00:00:00Z</dc:date>
      <dc:creator>Anastasios Stasinopoulos</dc:creator>
    </item>
    <item>
      <title>BadRabbit Ransomware Attack</title>
      <link>https://www.obrela.com/resources/labs/badrabbit-ransomware-attack</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/badrabbit-ransomware-attack?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="BadRabbit Ransomware Attack" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A new ransomware campaign by the name BadRabbit has targeted Russia, Turkey, Ukraine, Bulgaria, Japan and other countries.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/badrabbit-ransomware-attack?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="BadRabbit Ransomware Attack" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A new ransomware campaign by the name BadRabbit has targeted Russia, Turkey, Ukraine, Bulgaria, Japan and other countries.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fbadrabbit-ransomware-attack&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 13 Jun 2018 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/badrabbit-ransomware-attack</guid>
      <dc:date>2018-06-13T00:00:00Z</dc:date>
      <dc:creator>The Obrela LABS Team</dc:creator>
    </item>
    <item>
      <title>Bypassing Insufficient Blacklisting</title>
      <link>https://www.obrela.com/resources/labs/bypassing-insufficient-blacklisting</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/bypassing-insufficient-blacklisting?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="Bypassing Insufficient Blacklisting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h3 class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt;&lt;strong&gt;Bypassing insufficient blacklisting: Brief introduction&lt;/strong&gt;&lt;/h3&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;Operating system (OS) command injection attack is a variant of code injection attacks which are considered a major security threat that in fact, is classified as No. 1 on the 2013 OWASP top ten web security risks [1]. There are many types of code injection attacks including:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;SQL injection [2]&lt;/li&gt; 
  &lt;li&gt;Cross Site Scripting [3]&lt;/li&gt; 
  &lt;li&gt;OS command injection [4]&lt;/li&gt; 
  &lt;li&gt;XPath injection [5]&lt;/li&gt; 
  &lt;li&gt;LDAP injection [6]&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;OS command injection attacks may occur in applications that accept user provided input and execute OS commands using as parameters the received input. They have been discovered in web applications hosted in web servers (Windows or Linux) as well as in web-based management interfaces of networking devices, such as home/office routers, IP cameras, IP PBX applications and network printers. Moreover, command injection vulnerabilities can be found in IoT devices. However, the injected OS commands are usually executed with the same permissions that the application possesses (i.e. root). OS command injection attacks are possible in most cases due to lack of correct input data validation, which can be manipulated by the attacker (web forms, cookies, HTTP headers etc.)&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Detecting and exploiting command injection flaws&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Due to the fact that there are not many tools to automate the process of detecting and exploiting command injection vulnerabilities, in this blog post Commix tool will be used. Commix (a short for [&lt;strong&gt;COMM&lt;/strong&gt;]and [&lt;strong&gt;I&lt;/strong&gt;]njection e[&lt;strong&gt;X&lt;/strong&gt;]ploiter) is an automated tool aiming to facilitate web developers, penetration testers and security researchers to test web applications with the view to find bugs, errors or vulnerabilities related to command injection attacks. It is important to note that the module is capable of performing command injection not only in the HTTP GET / POST parameters, but also in HTTP parameters, such as HTTP cookie, HTTP user-agent and referrer header values. The tool is written in Python (version 2.6. or 2.7) and runs in both Unix/Linux and Windows operating systems. Commix is free to download through the GitHub repository [7]. It is worth mentioning that Commix comes preinstalled in many security-oriented OS’s including the well-known Kali Linux [8], while its capabilities have been presented in the BlackHat Europe 2015 Security Conference (Netherlands, Amsterdam) [9].&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Attack scenarios and lab setup&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;The main objective of this article is to examine the detection and exploitation capabilities of Commix against blacklisting techniques. The general idea behind blacklisting is to check for malicious patterns before allowing the execution of users input. More specifically, in the case of OS command injection attack, a blacklist can strip out from the users’ input all “suspicious” characters (i.e. “;”,”|”,”&amp;amp;”, etc.). However, a basic disadvantage of blacklisting, which greatly limits its effectiveness, is that the attacker can discover a variation of the command injection attack vectors not included in the blacklist and, hence, he can launch the attack successfully. In order to be able to get a reliable sample of checks against the most common blacklisting techniques, the&amp;nbsp;&lt;em&gt;Damn Vulnerable Web Application&lt;/em&gt;&amp;nbsp;(DVWA) v1.10 [10] was installed on a Debian Linux (3.16.0-4) operating system. DVWA is a free, open source PHP/MySQL web application that supports four different security levels, low, medium, high or impossible. The security level changes the vulnerability level of DVWA:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Low:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This security level is completely vulnerable and has no security countermeasures at all. Its use is to be as an example of how web application vulnerabilities manifest through bad coding practices and to serve as a platform to teach or learn basic exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Medium:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This setting is mainly to give an example to the user of bad security practices, where the developer has tried but failed to secure an application. It also acts as a challenge to users to refine their exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;High:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This option is an extension to the medium difficulty, with a mixture of harder or alternative bad practices to attempt to secure the code. The vulnerability may not allow the same extent of the exploitation, similar in various CTF competitions.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Impossible:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This level should be secure against all vulnerabilities. It is used to compare the vulnerable source code to the secure source code. (Prior to DVWA v1.9, this level was known as ‘high’).&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;DVWA also comes with an outdated (v0.6) Web Application Firewall (WAF) called PHPIDS. PHPIDS (PHP-Intrusion Detection System) [11] is a security layer for PHP based web applications. PHPIDS works by filtering any user’s supplied input against a blacklist of potentially malicious code. It is used in DVWA to serve as a live example of how WAFs can help improve security and in some cases how WAFs can be circumvented. At this point it is worth noting that during this research, the latest stable version (v0.7) [12] of PHPIDS was installed in DVWA.&lt;/p&gt; 
 &lt;p&gt;All the experiments were mainly conducted in two separate rounds of checks:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;In the first round of security checks, attacks were attempted at all security levels of DVWA without the PHPIDS WAF being activated.&lt;/li&gt; 
  &lt;li&gt;In the second round of security checks, exactly the same attacks were attempted as the first set of checks, but with the PHPIDS WAF enabled during the detection and exploitation procedure.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;h3&gt;&lt;strong&gt;Detection and exploitation results&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;It is summarized below, the detection and exploitation results of the first and the second round of security checks that were conducted against the vulnerable “ip” POST parameter of “/vulnerabilities/exec/” in DVWA against all* supported security levels (from Low to Impossible).&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;&lt;em&gt;*&amp;nbsp;&lt;/em&gt;&lt;/strong&gt;&lt;em&gt;On both rounds of&amp;nbsp;&lt;/em&gt;security checks&lt;em&gt;, in the “Impossible” security level, Commix did not detect any vulnerability (as expected) because this level is not meant to be exploitable.&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;1&lt;sup&gt;st&lt;/sup&gt;&amp;nbsp;Round of checks: PHPIDS 0.7 WAF&amp;nbsp;&lt;u&gt;disabled&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;(Table 1):&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Regarding the “Low” and “Medium” security levels, Commix successfully identified and exploited the command injection vulnerability&amp;nbsp;&lt;strong&gt;with every supported&lt;/strong&gt;&amp;nbsp;exploitation technique.&lt;/li&gt; 
  &lt;li&gt;Finally, in the “High” security level, although more strict security measures – in order to secure the code – were applied (i.e., better characters blacklisting) Commix successfully identified and exploited the command injection vulnerability using&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation technique.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 1: Succeeded command injection attacks with PHPIDS disabled.&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;2&lt;sup&gt;nd&lt;/sup&gt;&amp;nbsp;Round of checks: PHPIDS 0.7 WAF&amp;nbsp;&lt;u&gt;enabled&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;(Table 2):&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Concerning the “Low” and “Medium” security levels, Commix successfully identified and exploited the command injection vulnerabilities using&lt;strong&gt;&amp;nbsp;results-based&lt;/strong&gt;&amp;nbsp;and&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;Also, in “High” security level, Commix successfully identified and exploited the OS command injection vulnerabilities using the&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation technique.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 2: Succeeded command injection attacks with the PHPIDS enabled.&lt;/p&gt; 
 &lt;p&gt;Lastly it is worth mentioning that, even though the remote command execution protection filter that is used by the PHPIDS v0.7 to prevent remote OS command injection attacks seems quite weak (on this we will refer later) specific characters (i.e “$”, “{“,”}”,”))” etc) which are used in most payloads were detected. After further analysis on that issue it was identified that this happens due to overlays by other irrelevant WAF filters. In order to circumvent this restriction the “–backticks” switch (which uses the backtick (`) instead of the “$()” for command substitution [13]) was used.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Analyzing the weak filter of PHPIDS v0.7&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;As it has been already mentioned, PHPIDS 0.7 does not protect against OS command injection attacks. The filter that is used for protection against this type of attacks is included in the “default_filter.json” and “default_filter.xml” files. More specifically the filter with id “74” checks only for attempts to execute OS commands, such “ping&amp;nbsp; -n 3 127.0.0.1 ”, ping localhost -n 3” etc as presented below:&lt;/p&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;pre class="language-bash"&gt;&lt;code&gt;ping(.*)[\-(.*)\w|\w(.*)\-]&lt;/code&gt;&lt;/pre&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;p&gt;Moreover, we came to the point to suggest an additional regular expression for the aforementioned filter in such way all the attempted payloads have failed due to all the symbols used for OS command injection attacks are now being detected and blocked by the newly proposed filter:&lt;/p&gt; 
 &lt;div&gt; 
  &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;(?:[^|;|&amp;amp;|\||\&amp;lt;|\&amp;gt;|`|\$|\(|\)|\{|\}]\W*?\b)&lt;/code&gt;&lt;/pre&gt; 
  &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
  &lt;p&gt;Finally, the Table 3 below represents all the failed attempts to detect and exploit OS command injection vulnerabilities against the vulnerable “ip” POST parameter of “vulnerabilities/exec/”, after the new rule has been added.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 3:&amp;nbsp; Failed command injection attacks after PHPIDS updated filter&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Conclusions&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Concluding all the above, this article was mainly focused on the weak blacklisting features, as provided by all security levels of DVWA, combined with the latest stable version of the PHPIDS WAF. Once it was identified that Commix was able to bypass the weak blacklisting filters on each security level (i.e. Low, Medium, and High) with the presence of the latest stable PHPIDS WAF, a new rule (that successfully blocks all the exploitation attempts) was proposed.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/h3&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/Code_Injection"&gt;https://www.owasp.org/index.php/Code_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/SQL_Injection"&gt;https://www.owasp.org/index.php/SQL_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/xss"&gt;https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/index.php/Command_Injection"&gt;https://www.owasp.org/index.php/Command_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/XPATH_Injection"&gt;https://www.owasp.org/index.php/XPATH_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html"&gt;https://www.owasp.org/index.php/LDAP_injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/commixproject/commix"&gt;https://github.com/commixproject/commix&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://tools.kali.org/exploitation-tools/commix"&gt;https://tools.kali.org/exploitation-tools/commix&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.blackhat.com/docs/eu-15/materials/eu-15-Stasinopoulos-Commix-Detecting-And-Exploiting-Command-Injection-Flaws.pdf"&gt;https://www.blackhat.com/docs/eu-15/materials/eu-15-Stasinopoulos-Commix-Detecting-And-Exploiting-Command-Injection-Flaws.pdf&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/digininja/DVWA"&gt;https://github.com/ethicalhack3r/DVWA&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/PHPIDS/PHPIDS"&gt;https://github.com/PHPIDS/PHPIDS&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/PHPIDS/PHPIDS/releases/tag/0.7"&gt;https://github.com/PHPIDS/PHPIDS/releases/tag/0.7&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://tldp.org/LDP/abs/html/commandsub.html"&gt;http://tldp.org/LDP/abs/html/commandsub.html&lt;/a&gt;&lt;/li&gt; 
 &lt;/ol&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/bypassing-insufficient-blacklisting?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/new-Jun-26-2026-10-11-35-3615-AM.png" alt="Bypassing Insufficient Blacklisting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h3 class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt;&lt;strong&gt;Bypassing insufficient blacklisting: Brief introduction&lt;/strong&gt;&lt;/h3&gt; 
&lt;div class="ob-col-60 ob-col-md mt-120 mt-md-50 ob-simple-text t-black"&gt; 
 &lt;p&gt;Operating system (OS) command injection attack is a variant of code injection attacks which are considered a major security threat that in fact, is classified as No. 1 on the 2013 OWASP top ten web security risks [1]. There are many types of code injection attacks including:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;SQL injection [2]&lt;/li&gt; 
  &lt;li&gt;Cross Site Scripting [3]&lt;/li&gt; 
  &lt;li&gt;OS command injection [4]&lt;/li&gt; 
  &lt;li&gt;XPath injection [5]&lt;/li&gt; 
  &lt;li&gt;LDAP injection [6]&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;OS command injection attacks may occur in applications that accept user provided input and execute OS commands using as parameters the received input. They have been discovered in web applications hosted in web servers (Windows or Linux) as well as in web-based management interfaces of networking devices, such as home/office routers, IP cameras, IP PBX applications and network printers. Moreover, command injection vulnerabilities can be found in IoT devices. However, the injected OS commands are usually executed with the same permissions that the application possesses (i.e. root). OS command injection attacks are possible in most cases due to lack of correct input data validation, which can be manipulated by the attacker (web forms, cookies, HTTP headers etc.)&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Detecting and exploiting command injection flaws&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Due to the fact that there are not many tools to automate the process of detecting and exploiting command injection vulnerabilities, in this blog post Commix tool will be used. Commix (a short for [&lt;strong&gt;COMM&lt;/strong&gt;]and [&lt;strong&gt;I&lt;/strong&gt;]njection e[&lt;strong&gt;X&lt;/strong&gt;]ploiter) is an automated tool aiming to facilitate web developers, penetration testers and security researchers to test web applications with the view to find bugs, errors or vulnerabilities related to command injection attacks. It is important to note that the module is capable of performing command injection not only in the HTTP GET / POST parameters, but also in HTTP parameters, such as HTTP cookie, HTTP user-agent and referrer header values. The tool is written in Python (version 2.6. or 2.7) and runs in both Unix/Linux and Windows operating systems. Commix is free to download through the GitHub repository [7]. It is worth mentioning that Commix comes preinstalled in many security-oriented OS’s including the well-known Kali Linux [8], while its capabilities have been presented in the BlackHat Europe 2015 Security Conference (Netherlands, Amsterdam) [9].&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Attack scenarios and lab setup&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;The main objective of this article is to examine the detection and exploitation capabilities of Commix against blacklisting techniques. The general idea behind blacklisting is to check for malicious patterns before allowing the execution of users input. More specifically, in the case of OS command injection attack, a blacklist can strip out from the users’ input all “suspicious” characters (i.e. “;”,”|”,”&amp;amp;”, etc.). However, a basic disadvantage of blacklisting, which greatly limits its effectiveness, is that the attacker can discover a variation of the command injection attack vectors not included in the blacklist and, hence, he can launch the attack successfully. In order to be able to get a reliable sample of checks against the most common blacklisting techniques, the&amp;nbsp;&lt;em&gt;Damn Vulnerable Web Application&lt;/em&gt;&amp;nbsp;(DVWA) v1.10 [10] was installed on a Debian Linux (3.16.0-4) operating system. DVWA is a free, open source PHP/MySQL web application that supports four different security levels, low, medium, high or impossible. The security level changes the vulnerability level of DVWA:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Low:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This security level is completely vulnerable and has no security countermeasures at all. Its use is to be as an example of how web application vulnerabilities manifest through bad coding practices and to serve as a platform to teach or learn basic exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Medium:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This setting is mainly to give an example to the user of bad security practices, where the developer has tried but failed to secure an application. It also acts as a challenge to users to refine their exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;High:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This option is an extension to the medium difficulty, with a mixture of harder or alternative bad practices to attempt to secure the code. The vulnerability may not allow the same extent of the exploitation, similar in various CTF competitions.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;&lt;u&gt;Impossible:&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;This level should be secure against all vulnerabilities. It is used to compare the vulnerable source code to the secure source code. (Prior to DVWA v1.9, this level was known as ‘high’).&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p&gt;DVWA also comes with an outdated (v0.6) Web Application Firewall (WAF) called PHPIDS. PHPIDS (PHP-Intrusion Detection System) [11] is a security layer for PHP based web applications. PHPIDS works by filtering any user’s supplied input against a blacklist of potentially malicious code. It is used in DVWA to serve as a live example of how WAFs can help improve security and in some cases how WAFs can be circumvented. At this point it is worth noting that during this research, the latest stable version (v0.7) [12] of PHPIDS was installed in DVWA.&lt;/p&gt; 
 &lt;p&gt;All the experiments were mainly conducted in two separate rounds of checks:&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;In the first round of security checks, attacks were attempted at all security levels of DVWA without the PHPIDS WAF being activated.&lt;/li&gt; 
  &lt;li&gt;In the second round of security checks, exactly the same attacks were attempted as the first set of checks, but with the PHPIDS WAF enabled during the detection and exploitation procedure.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;h3&gt;&lt;strong&gt;Detection and exploitation results&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;It is summarized below, the detection and exploitation results of the first and the second round of security checks that were conducted against the vulnerable “ip” POST parameter of “/vulnerabilities/exec/” in DVWA against all* supported security levels (from Low to Impossible).&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;&lt;em&gt;*&amp;nbsp;&lt;/em&gt;&lt;/strong&gt;&lt;em&gt;On both rounds of&amp;nbsp;&lt;/em&gt;security checks&lt;em&gt;, in the “Impossible” security level, Commix did not detect any vulnerability (as expected) because this level is not meant to be exploitable.&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;1&lt;sup&gt;st&lt;/sup&gt;&amp;nbsp;Round of checks: PHPIDS 0.7 WAF&amp;nbsp;&lt;u&gt;disabled&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;(Table 1):&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Regarding the “Low” and “Medium” security levels, Commix successfully identified and exploited the command injection vulnerability&amp;nbsp;&lt;strong&gt;with every supported&lt;/strong&gt;&amp;nbsp;exploitation technique.&lt;/li&gt; 
  &lt;li&gt;Finally, in the “High” security level, although more strict security measures – in order to secure the code – were applied (i.e., better characters blacklisting) Commix successfully identified and exploited the command injection vulnerability using&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation technique.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 1: Succeeded command injection attacks with PHPIDS disabled.&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;2&lt;sup&gt;nd&lt;/sup&gt;&amp;nbsp;Round of checks: PHPIDS 0.7 WAF&amp;nbsp;&lt;u&gt;enabled&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;(Table 2):&lt;/p&gt; 
 &lt;ul&gt; 
  &lt;li&gt;Concerning the “Low” and “Medium” security levels, Commix successfully identified and exploited the command injection vulnerabilities using&lt;strong&gt;&amp;nbsp;results-based&lt;/strong&gt;&amp;nbsp;and&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation techniques.&lt;/li&gt; 
  &lt;li&gt;Also, in “High” security level, Commix successfully identified and exploited the OS command injection vulnerabilities using the&amp;nbsp;&lt;strong&gt;file-based&amp;nbsp;&lt;/strong&gt;exploitation technique.&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;PASSED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 2: Succeeded command injection attacks with the PHPIDS enabled.&lt;/p&gt; 
 &lt;p&gt;Lastly it is worth mentioning that, even though the remote command execution protection filter that is used by the PHPIDS v0.7 to prevent remote OS command injection attacks seems quite weak (on this we will refer later) specific characters (i.e “$”, “{“,”}”,”))” etc) which are used in most payloads were detected. After further analysis on that issue it was identified that this happens due to overlays by other irrelevant WAF filters. In order to circumvent this restriction the “–backticks” switch (which uses the backtick (`) instead of the “$()” for command substitution [13]) was used.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Analyzing the weak filter of PHPIDS v0.7&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;As it has been already mentioned, PHPIDS 0.7 does not protect against OS command injection attacks. The filter that is used for protection against this type of attacks is included in the “default_filter.json” and “default_filter.xml” files. More specifically the filter with id “74” checks only for attempts to execute OS commands, such “ping&amp;nbsp; -n 3 127.0.0.1 ”, ping localhost -n 3” etc as presented below:&lt;/p&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;pre class="language-bash"&gt;&lt;code&gt;ping(.*)[\-(.*)\w|\w(.*)\-]&lt;/code&gt;&lt;/pre&gt; 
 &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
 &lt;p&gt;Moreover, we came to the point to suggest an additional regular expression for the aforementioned filter in such way all the attempted payloads have failed due to all the symbols used for OS command injection attacks are now being detected and blocked by the newly proposed filter:&lt;/p&gt; 
 &lt;div&gt; 
  &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
  &lt;pre class="language-bash"&gt;&lt;code&gt;(?:[^|;|&amp;amp;|\||\&amp;lt;|\&amp;gt;|`|\$|\(|\)|\{|\}]\W*?\b)&lt;/code&gt;&lt;/pre&gt; 
  &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
  &lt;p&gt;Finally, the Table 3 below represents all the failed attempts to detect and exploit OS command injection vulnerabilities against the vulnerable “ip” POST parameter of “vulnerabilities/exec/”, after the new rule has been added.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;table width="638" style="border-width: 1px; border-style: solid;"&gt; 
  &lt;tbody&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;RESULTS-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TIME-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FILE-BASED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;TEMPFILE-BASED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;LOW&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;HIGH&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
   &lt;tr&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;IMPOSSIBLE&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
    &lt;td style="border-width: 1px; border-style: solid; padding: 0px;"&gt;&lt;strong&gt;FAILED&lt;/strong&gt;&lt;/td&gt; 
   &lt;/tr&gt; 
  &lt;/tbody&gt; 
 &lt;/table&gt; 
 &lt;p&gt;Table 3:&amp;nbsp; Failed command injection attacks after PHPIDS updated filter&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;Conclusions&lt;/strong&gt;&lt;/h3&gt; 
 &lt;p&gt;Concluding all the above, this article was mainly focused on the weak blacklisting features, as provided by all security levels of DVWA, combined with the latest stable version of the PHPIDS WAF. Once it was identified that Commix was able to bypass the weak blacklisting filters on each security level (i.e. Low, Medium, and High) with the presence of the latest stable PHPIDS WAF, a new rule (that successfully blocks all the exploitation attempts) was proposed.&lt;/p&gt; 
 &lt;h3&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/h3&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/Code_Injection"&gt;https://www.owasp.org/index.php/Code_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/SQL_Injection"&gt;https://www.owasp.org/index.php/SQL_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/xss"&gt;https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/index.php/Command_Injection"&gt;https://www.owasp.org/index.php/Command_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://owasp.org/www-community/attacks/XPATH_Injection"&gt;https://www.owasp.org/index.php/XPATH_Injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html"&gt;https://www.owasp.org/index.php/LDAP_injection&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/commixproject/commix"&gt;https://github.com/commixproject/commix&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://tools.kali.org/exploitation-tools/commix"&gt;https://tools.kali.org/exploitation-tools/commix&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.blackhat.com/docs/eu-15/materials/eu-15-Stasinopoulos-Commix-Detecting-And-Exploiting-Command-Injection-Flaws.pdf"&gt;https://www.blackhat.com/docs/eu-15/materials/eu-15-Stasinopoulos-Commix-Detecting-And-Exploiting-Command-Injection-Flaws.pdf&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/digininja/DVWA"&gt;https://github.com/ethicalhack3r/DVWA&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/PHPIDS/PHPIDS"&gt;https://github.com/PHPIDS/PHPIDS&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://github.com/PHPIDS/PHPIDS/releases/tag/0.7"&gt;https://github.com/PHPIDS/PHPIDS/releases/tag/0.7&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://tldp.org/LDP/abs/html/commandsub.html"&gt;http://tldp.org/LDP/abs/html/commandsub.html&lt;/a&gt;&lt;/li&gt; 
 &lt;/ol&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fbypassing-insufficient-blacklisting&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 23 Feb 2018 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/bypassing-insufficient-blacklisting</guid>
      <dc:date>2018-02-23T00:00:00Z</dc:date>
      <dc:creator>No Author</dc:creator>
    </item>
    <item>
      <title>Undetectable Metasploit WAR</title>
      <link>https://www.obrela.com/resources/labs/undetectable-metasploit-war</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/undetectable-metasploit-war?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/RiskAlignedCyberSecurity-Jun-26-2026-10-11-26-8678-AM.jpg" alt="Undetectable Metasploit WAR" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A possible attack path during a penetration test is having access to the administrative console of a JAVA Application Server (like WAS, JBOSS and Tomcat) installed on a Windows server with default or guessable (e.g. through brute-force) administrative credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/undetectable-metasploit-war?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/RiskAlignedCyberSecurity-Jun-26-2026-10-11-26-8678-AM.jpg" alt="Undetectable Metasploit WAR" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A possible attack path during a penetration test is having access to the administrative console of a JAVA Application Server (like WAS, JBOSS and Tomcat) installed on a Windows server with default or guessable (e.g. through brute-force) administrative credentials.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fundetectable-metasploit-war&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 04 Oct 2016 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/undetectable-metasploit-war</guid>
      <dc:date>2016-10-04T00:00:00Z</dc:date>
      <dc:creator>No Author</dc:creator>
    </item>
    <item>
      <title>Vulnerability in Windows http.sys Could Allow DOS or Remote Code Execution</title>
      <link>https://www.obrela.com/resources/labs/vulnerability-in-windows-http-sys-could-allow-dos-or-remote-code-execution</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/vulnerability-in-windows-http-sys-could-allow-dos-or-remote-code-execution?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract-Jun-26-2026-10-11-36-4674-AM.png" alt="Vulnerability in Windows http.sys Could Allow DOS or Remote Code Execution" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Yesterday Microsoft has patched a critical vulnerability in Windows HTTP stack (http.sys), which would have extreme consequences if an exploit is publicly disclosed.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.obrela.com/resources/labs/vulnerability-in-windows-http-sys-could-allow-dos-or-remote-code-execution?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.obrela.com/hubfs/Imported_Blog_Media/Obrela_Abstract-Jun-26-2026-10-11-36-4674-AM.png" alt="Vulnerability in Windows http.sys Could Allow DOS or Remote Code Execution" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Yesterday Microsoft has patched a critical vulnerability in Windows HTTP stack (http.sys), which would have extreme consequences if an exploit is publicly disclosed.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=26076500&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.obrela.com%2Fresources%2Flabs%2Fvulnerability-in-windows-http-sys-could-allow-dos-or-remote-code-execution&amp;amp;bu=https%253A%252F%252Fwww.obrela.com%252Fresources%252Flabs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 14 Apr 2015 00:00:00 GMT</pubDate>
      <guid>https://www.obrela.com/resources/labs/vulnerability-in-windows-http-sys-could-allow-dos-or-remote-code-execution</guid>
      <dc:date>2015-04-14T00:00:00Z</dc:date>
      <dc:creator>No Author</dc:creator>
    </item>
  </channel>
</rss>
