RCE Holistic Methodology
This is the index for remote code execution on web targets. It links to every chapter. Read it top to bottom once, then use it as a jump table on a real engagement.
Each chapter is self contained and has a checklist at the top. Sources used across all chapters: PayloadsAllTheThings, HackTricks, PortSwigger Web Security Academy, OWASP WSTG, OWASP Top 10, Bugcrowd RCE 101 and VRT, Synack blog, ProjectDiscovery blog, HackerOne Hacktivity, OffSec blog, Wiz blog, GitHub PoC repos, HTB writeups, and the books “Attacking and Exploiting Modern Web Applications” by Onofri, “Web Security Practice”, and “The Art of Discovering Web Application Vulnerabilities”.
1. What RCE is
Remote code execution is any flaw that lets you run your own code or commands on a target you do not own. On web targets it is the highest severity class because it collapses every other control at once.
- Definition: you supply input, the server turns that input into executed code or a spawned process.
- Why it is the top severity: once you run code, authentication, authorization, input validation, and business logic no longer protect anything. You are inside.
- RCE vs ACE vs command injection: Arbitrary Code Execution (ACE) means you run code in the target process (for example a deserialization gadget running in the JVM). Command injection means your input reaches a shell and you run OS commands. RCE is the umbrella term for both when the attacker is remote. Command injection and ACE are two roads to RCE.
- Common impact: full server compromise, credential theft from memory and disk, lateral movement into the internal network, data theft, and persistence through cron, services, or implants.
2. Foundations
Before you hunt, understand how a request becomes a running process.
- How server side languages execute commands and evaluate code.
- Shell metacharacters and why a single unescaped character changes everything.
- The request to code execution path in a typical web app: input, sink, interpreter, process.
Read the chapter: Foundations
3. Entry points
The ways untrusted input reaches an interpreter or a shell.
- Command injection
- Code injection via eval
- Deserialization (Java, PHP, Python, .NET, YAML)
- File upload to webshell
- Server side template injection
- Expression injection (SpEL, OGNL, MVEL)
- Log4Shell and JNDI injection
- SSRF to Redis, FastCGI, Docker socket
- LFI to RCE
- SQL injection to RCE
- XXE to RCE
Read the chapter: Entry points
4. Detection
How to confirm a candidate is really executing your input.
- Manual detection per class
- Fuzzing for injection points
- Out of band confirmation with interactsh
- Reading error messages and stack traces
Read the chapter: Detection
5. Exploitation
Turning a proof into a stable foothold.
- Payload construction per language
- Reverse shell one liners
- TTY upgrade
- Persistence
Read the chapter: Exploitation
6. Chaining
RCE is usually the last link, not the first.
- RCE as the final step of a chain
- Examples: SSRF plus Redis plus cron equals RCE. IDOR plus deserialization equals RCE. XSS plus Electron equals RCE.
Read the chapter: Chaining
7. Case studies
Real bugs, dissected.
- CVEs: React2Shell CVE 2025 55182, CVE 2025 33053 WebDAV, CVE 2025 14558 FreeBSD rtsold, CVE 2025 8110 Gogs, CVE 2025 63721 HummerRisk, CVE 2025 64050 REDAXO, Log4Shell CVE 2021 44228.
- HTB machines: Pterodactyl, Kobold, OneTwoSeven, Planning, GiveBack, Analytics, Reactor, CCTV, Editorial.
Read the chapter: Case studies
8. Tools
The kit that covers most RCE work.
- Burp Suite, interactsh, tplmap, ysoserial, ysoserial.net, PHPGGC, Commix, Nuclei, Searchsploit, sqlmap, Metasploit, revshells.com.
Read the chapter: Tools
9. Bypasses
When a filter or WAF sits in the way.
- WAF bypass for command injection
- Encoding, casing, comment insertion
- Shell alias evasion
- trap command bypass
- Pickle scanner bypass
- SpEL WAF bypass
Read the chapter: Bypasses
10. Reporting
A finding is only as good as its report.
- Report template
- Severity and CVSS
- PoC format
- Impact statement
- Remediation notes
Read the chapter: Reporting