All tools

Web Application

Commix

Automated command injection exploitation tool.

intermediate
Linux
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Suspected OS command injection in web parameters.

How

Pass URL/params; let it detect and spawn shell if vulnerable.

Why

Speeds up command injection validation in labs/CTFs.

Commands & usage

commix --url='http://target/page.php?input=test'

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

command-injection
web

Related in Web Application