0 of 0 steps completed

Thirteen phases, from command execution primitives to chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Phases 3, 4, and 6 carry the techniques that turn a single finding into code execution, so spend the most time there.

Phase 1: RCE Fundamentals

Step 1.1 What RCE is and why it matters
Step 1.2 Command execution primitives per language
Step 1.3 Shell metacharacters and injection operators

Phase 2: Command Injection Deep Dive

Step 2.1 Basic and blind command injection
Step 2.2 Data exfiltration via DNS and OOB
Step 2.3 WAF bypass for command injection

Phase 3: Deserialization RCE

Step 3.1 Java deserialization
Step 3.2 PHP deserialization
Step 3.3 Python deserialization
Step 3.4 .NET deserialization

Phase 4: SSTI to RCE

Step 4.1 SSTI detection and fingerprinting
Step 4.2 Jinja2, Twig, and Freemarker RCE
Step 4.3 Advanced SSTI without quotes or plugins

Phase 5: File Upload to Webshell

Step 5.1 Basic webshell upload
Step 5.2 Extension, MIME, and magic byte bypass
Step 5.3 .htaccess and web.config upload

Phase 6: Log4Shell, SSRF, LFI, SQLi, XXE to RCE

Step 6.1 Log4Shell (CVE-2021-44228)
Step 6.2 SSRF to RCE
Step 6.3 LFI to RCE
Step 6.4 SQLi to RCE
Step 6.5 XXE to RCE

Phase 7: Prototype Pollution to RCE

Step 7.1 Client-side prototype pollution
Step 7.2 Server-side prototype pollution to RCE

Phase 8: CI/CD Pipeline RCE

Step 8.1 GitLab CI/CD pipeline security
Step 8.2 GitHub Actions RCE

Phase 9: Chaining RCE for High Impact

Step 9.1 Chaining basics
Step 9.2 High-impact chains
Step 9.3 Bug bounty targets

Phase 10: Tools and Programming

Step 10.1 RCE tools
Step 10.2 Python for RCE automation

Phase 11: Books, Podcasts, and Videos

Step 11.1 Essential books
  • BookHacking: The Art of Exploitation, Jon Erickson
  • BookThe Web Application Hacker's Handbook, Stuttard and Pinto
  • BookThe Hacker Playbook 3, Peter Kim
Step 11.2 Podcasts
Step 11.3 YouTube playlists and channels

Phase 12: Labs and Practice

Step 12.1 HTB Academy and machines
Step 12.2 PortSwigger Web Security Academy
Step 12.3 CTF and bug bounty practice

Phase 13: Exam Preparation and Career

Step 13.1 CWES and CWEE RCE topics
Step 13.2 Bug bounty workflow