RCE Mastery Roadmap: Command Injection, Deserialization, SSTI, and Chaining
0 of 0 steps completed
Thirteen phases, from command execution primitives to chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Phases 3, 4, and 6 carry the techniques that turn a single finding into code execution, so spend the most time there.
Phase 1: RCE Fundamentals
Step 1.1 What RCE is and why it matters
- BookThe Web Application Hacker's Handbook, Chapters 11 and 12, Stuttard and Pinto
- BookHacking: The Art of Exploitation, Jon Erickson
- PortSwiggerOS command injection labs
- YouTubeLiveOverflow, exploitation concepts
Step 1.2 Command execution primitives per language
- BookWeb Application Security, Andrew Hoffman (code execution chapters)
- HTB AcademyCommand Injections
- PortSwiggerOS command injection (all levels)
- HackTricksCommand injection per language
- YouTubeIppSec, command injection walkthroughs
Step 1.3 Shell metacharacters and injection operators
- HTB AcademyCommand Injections, all sections
- PayloadsPayloadsAllTheThings, Command Injection
- ToolCommix
Phase 2: Command Injection Deep Dive
Step 2.1 Basic and blind command injection
- HTB AcademyCommand Injections, blind sections
- PortSwiggerBlind OS command injection labs
- Toolinteractsh, out-of-band detection
Step 2.2 Data exfiltration via DNS and OOB
- HackTricksBlind and out-of-band command injection
- Toolinteractsh, Burp Collaborator
Step 2.3 WAF bypass for command injection
- HackTricksFilter and WAF bypass notes
- ToolWAFW00F, WAF fingerprinting
- YouTubeSTÖK, WAF bypass techniques
Phase 3: Deserialization RCE
Step 3.1 Java deserialization
- BookAttacking and Exploiting Modern Web Applications, Chapter 6, Onofri and Onofri
- HTB AcademyIntroduction to Deserialization Attacks
- PortSwiggerInsecure deserialization labs
- GitHubfrohoff/ysoserial
Step 3.2 PHP deserialization
- HTB AcademyAdvanced Deserialization Attacks
- PortSwiggerPHP deserialization labs
- GitHubambionics/PHPGGC
- BlogAmbionics, PHP object injection research
Step 3.3 Python deserialization
- HTB AcademyDeserialization Attacks, Python section
- HackTricksPickle and Python deserialization
- PayloadsPayloadsAllTheThings, Insecure Deserialization
Step 3.4 .NET deserialization
- HTB AcademyAdvanced Deserialization Attacks, .NET section
- PortSwiggerInsecure deserialization labs
- GitHubpwntester/ysoserial.net
Phase 4: SSTI to RCE
Step 4.1 SSTI detection and fingerprinting
- HTB AcademyServer-side Attacks, SSTI section
- PortSwiggerServer-side template injection labs
- Tooltplmap
Step 4.2 Jinja2, Twig, and Freemarker RCE
- PortSwiggerSSTI labs (all levels)
- HackTricksSSTI per engine
- PayloadsPayloadsAllTheThings, SSTI
- YouTubeIppSec, SSTI to RCE
Step 4.3 Advanced SSTI without quotes or plugins
- HackTricksFilter bypass and restricted SSTI
- PayloadsPayloadsAllTheThings, SSTI bypasses
- HTB MachineWeb machines featuring SSTI (retired list)
Phase 5: File Upload to Webshell
Step 5.1 Basic webshell upload
- HTB AcademyFile Upload Attacks
- PortSwiggerFile upload vulnerabilities labs
- PayloadsPayloadsAllTheThings, Upload Insecure Files
Step 5.2 Extension, MIME, and magic byte bypass
- HTB AcademyFile Upload Attacks, bypass sections
- PortSwiggerFile upload labs (all levels)
- HackTricksFile upload bypass
Step 5.3 .htaccess and web.config upload
- HackTrickshtaccess and web.config to RCE
- PortSwiggerFile upload labs
Phase 6: Log4Shell, SSRF, LFI, SQLi, XXE to RCE
Step 6.1 Log4Shell (CVE-2021-44228)
Step 6.2 SSRF to RCE
- PortSwiggerSSRF labs
- HackTricksSSRF to internal services and RCE
- HackerOneReport 1809193, SSRF
Step 6.3 LFI to RCE
- HTB AcademyFile Inclusion
- HackTricksLFI to RCE (wrappers, logs, sessions)
- PayloadsPayloadsAllTheThings, File Inclusion
Step 6.4 SQLi to RCE
- PortSwiggerSQL injection labs
- HackTricksSQLi to RCE (INTO OUTFILE, stacked queries)
- Toolsqlmap, os-shell
Step 6.5 XXE to RCE
- PortSwiggerXXE injection labs
- HackTricksXXE to RCE (expect wrapper)
- PayloadsPayloadsAllTheThings, XXE Injection
Phase 7: Prototype Pollution to RCE
Step 7.1 Client-side prototype pollution
- BookJavaScript for Hackers, Gareth Heyes
- PortSwiggerPrototype pollution labs
- HackTricksPrototype pollution
Step 7.2 Server-side prototype pollution to RCE
Phase 8: CI/CD Pipeline RCE
Step 8.1 GitLab CI/CD pipeline security
- DocGitLab CI/CD documentation
- Toolgitleaks, trufflehog for secrets in pipelines
Step 8.2 GitHub Actions RCE
Phase 9: Chaining RCE for High Impact
Step 9.1 Chaining basics
- GitHubKathanP19/HowToHunt, exploitation and impact
- HackerOneHacktivity, RCE chains
- BlogStudy disclosed chains where SSRF or deserialization escalates to RCE
Step 9.2 High-impact chains
Step 9.3 Bug bounty targets
Phase 10: Tools and Programming
Step 10.1 RCE tools
- ToolCommix, tplmap, interactsh
- Toolysoserial, PHPGGC, ysoserial.net
- ToolBurp Suite
Step 10.2 Python for RCE automation
- Toolrequests, sockets, and pwntools for custom exploit scripts
- DocRequests documentation
- GitHubKathanP19/HowToHunt, scripting references
Phase 11: Books, Podcasts, and Videos
Step 11.1 Essential books
- BookHacking: The Art of Exploitation, Jon Erickson
- BookThe Web Application Hacker's Handbook, Stuttard and Pinto
- BookThe Hacker Playbook 3, Peter Kim
Step 11.2 Podcasts
- PodcastDarknet Diaries
- PodcastCritical Thinking Bug Bounty Podcast
- PodcastSANS Internet Storm Center Stormcast
Step 11.3 YouTube playlists and channels
- YouTubeLiveOverflow, John Hammond
- YouTubeIppSec, STÖK
- YouTubePortSwigger, official labs
Phase 12: Labs and Practice
Step 12.1 HTB Academy and machines
- HTB AcademyCommand Injections, File Upload Attacks, File Inclusion, Server-side Attacks
- HTB MachineRetired web machines featuring deserialization, SSTI, and upload to RCE
Step 12.2 PortSwigger Web Security Academy
- PortSwiggerCommand injection, deserialization, SSTI
- PortSwiggerFile upload, SSRF, prototype pollution
Step 12.3 CTF and bug bounty practice
Phase 13: Exam Preparation and Career
Step 13.1 CWES and CWEE RCE topics
- HTB AcademyCWES path injection and upload modules
- HTB AcademyCWEE path advanced deserialization and SSTI
- PortSwiggerExpert labs as timed practice