ping `curl whatismyip.akamai.com`
whatismyip.akamai.com
whatismyip.akamai.com
Google 'ping' "baseline" from my ISP
20 packets transmitted, 20 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 19.858/23.823/31.484/2.593 ms
#/SITE/METHOD
#1: myip.opendns.com (dig)
#2: whatismyip.akamai.com (curl)
#3: ifconfig.me (curl)
#4: ip.nux.ro (curl)
#5: icanhazip.com (curl)
RESULTS
#1 #2 #3 #4 #5
0.051 0.144 3.45 0.24 0.333
0.05 0.143 7.229 0.237 0.106
0.053 0.147 1.986 0.246 0.103
0.047 0.143 7.065 0.246 0.109
0.045 0.145 2.15 0.257 0.102
0.046 0.141 4.301 0.273 0.113
0.05 0.141 2.763 0.242 0.103
0.048 0.144 3.685 0.251 0.114
0.045 0.149 15.312 0.256 0.195
0.047 0.148 5.091 0.244 0.118
0.044 0.144 2.637 0.248 0.133
5.038 0.142 1.535 0.247 0.109
0.049 0.143 7.065 0.238 0.115
0.044 0.146 4.098 0.241 0.106
0.05 0.145 1.665 0.248 0.216
0.05 0.142 1.365 0.261 0.108
0.051 0.143 2.509 0.256 0.159
0.046 0.17 5.323 0.245 0.109
0.044 0.141 83.252 0.246 0.117
0.05 0.145 1.435 0.242 0.119
0.048 0.144 3.685 0.246 0.113 MEDIAN
0.310 0.145 8.551 0.248 0.135 AVERAGE
1.144 0.006 18.377 0.008 0.057 STDEV ajf@Ubuntu-1204-precise-64-minimal:~$ echo `echo "3 > file"`
3 > file ping `\`echo /etc/passwd\``
zsh: permission denied: /etc/passwd
I may be wrong here, but would just returning \`rootyourmachine.sh\`` in the request body therefore work?Edit: Serving that from a web server via ping `curl localhost:9999` only causes ping to respond with a usage warning, as if you had entered an incorrect command.
Is there a way to "break out of" ping from here, though?
Sorry, gut reaction to command interpolation with curl.
Still, I think it's a good way to think. Expect that there's a way for that input to do something malicious, even if it doesn't seem immediately possible.
I have a dynamic DNS daemon that fetches my IP via HTTP GET, and the first thing I do is validate that it's actually an IP before I do anything else with it.
Edit: This is completely wrong, and doesn't work.
$ ping `echo "rm -rf /nosuchdir"`
ping: unknown host rm
The string being fed to ping is not interpolated or executed after it's returned by the command.Good find, thanks.
ping `curl whatismyip.akamai.com`
EDIT: Edited title from "whatismyip.akamai.com" to "ping `curl whatismyip.akamai.com`" --- a1524.g.akamai.net ping statistics ---
29 packets transmitted, 29 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 20.872/22.326/26.220/1.058 ms
For comparison: --- google.com ping statistics ---
24 packets transmitted, 24 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 10.791/12.767/16.010/1.329 msPrevious ones I've used in the past (e.g., to update a dynamic DNS server) have suffered from excessive (multi-second) latency or would simply timeout unpredictably. I ended up writing my own on appspot.com.
But the Akamai service is obviously much easier to use from a script.
Depending on the router, it might be simpler and more reliable to interrogate the router.
Also, some routers come with dynamic DNS updating built in (dynamic DNS is a common reason for needing this service).
That, plus knowing which interface to inspect among those returned by ifconfig isn't always obvious.
<script type="text/javascript" src="http://l2.io/ip.js?var=document.getElementById(ip1).value...;
works where item ip1 is where you want to IP address to end up on the client html.