This is the index for remote code execution on web targets. It links to every chapter. Read it top to bottom once, then use it as a jump table on a real engagement.

Each chapter is self contained and has a checklist at the top. Sources used across all chapters: PayloadsAllTheThings, HackTricks, PortSwigger Web Security Academy, OWASP WSTG, OWASP Top 10, Bugcrowd RCE 101 and VRT, Synack blog, ProjectDiscovery blog, HackerOne Hacktivity, OffSec blog, Wiz blog, GitHub PoC repos, HTB writeups, and the books “Attacking and Exploiting Modern Web Applications” by Onofri, “Web Security Practice”, and “The Art of Discovering Web Application Vulnerabilities”.

1. What RCE is

Remote code execution is any flaw that lets you run your own code or commands on a target you do not own. On web targets it is the highest severity class because it collapses every other control at once.

  • Definition: you supply input, the server turns that input into executed code or a spawned process.
  • Why it is the top severity: once you run code, authentication, authorization, input validation, and business logic no longer protect anything. You are inside.
  • RCE vs ACE vs command injection: Arbitrary Code Execution (ACE) means you run code in the target process (for example a deserialization gadget running in the JVM). Command injection means your input reaches a shell and you run OS commands. RCE is the umbrella term for both when the attacker is remote. Command injection and ACE are two roads to RCE.
  • Common impact: full server compromise, credential theft from memory and disk, lateral movement into the internal network, data theft, and persistence through cron, services, or implants.

2. Foundations

Before you hunt, understand how a request becomes a running process.

  • How server side languages execute commands and evaluate code.
  • Shell metacharacters and why a single unescaped character changes everything.
  • The request to code execution path in a typical web app: input, sink, interpreter, process.

Read the chapter: Foundations

3. Entry points

The ways untrusted input reaches an interpreter or a shell.

  • Command injection
  • Code injection via eval
  • Deserialization (Java, PHP, Python, .NET, YAML)
  • File upload to webshell
  • Server side template injection
  • Expression injection (SpEL, OGNL, MVEL)
  • Log4Shell and JNDI injection
  • SSRF to Redis, FastCGI, Docker socket
  • LFI to RCE
  • SQL injection to RCE
  • XXE to RCE

Read the chapter: Entry points

4. Detection

How to confirm a candidate is really executing your input.

  • Manual detection per class
  • Fuzzing for injection points
  • Out of band confirmation with interactsh
  • Reading error messages and stack traces

Read the chapter: Detection

5. Exploitation

Turning a proof into a stable foothold.

  • Payload construction per language
  • Reverse shell one liners
  • TTY upgrade
  • Persistence

Read the chapter: Exploitation

6. Chaining

RCE is usually the last link, not the first.

  • RCE as the final step of a chain
  • Examples: SSRF plus Redis plus cron equals RCE. IDOR plus deserialization equals RCE. XSS plus Electron equals RCE.

Read the chapter: Chaining

7. Case studies

Real bugs, dissected.

  • CVEs: React2Shell CVE 2025 55182, CVE 2025 33053 WebDAV, CVE 2025 14558 FreeBSD rtsold, CVE 2025 8110 Gogs, CVE 2025 63721 HummerRisk, CVE 2025 64050 REDAXO, Log4Shell CVE 2021 44228.
  • HTB machines: Pterodactyl, Kobold, OneTwoSeven, Planning, GiveBack, Analytics, Reactor, CCTV, Editorial.

Read the chapter: Case studies

8. Tools

The kit that covers most RCE work.

  • Burp Suite, interactsh, tplmap, ysoserial, ysoserial.net, PHPGGC, Commix, Nuclei, Searchsploit, sqlmap, Metasploit, revshells.com.

Read the chapter: Tools

9. Bypasses

When a filter or WAF sits in the way.

  • WAF bypass for command injection
  • Encoding, casing, comment insertion
  • Shell alias evasion
  • trap command bypass
  • Pickle scanner bypass
  • SpEL WAF bypass

Read the chapter: Bypasses

10. Reporting

A finding is only as good as its report.

  • Report template
  • Severity and CVSS
  • PoC format
  • Impact statement
  • Remediation notes

Read the chapter: Reporting