Skip to content
Anastasios Stasinopoulos edited this page Jan 13, 2016 · 66 revisions
Usage: python commix.py [options]

Options:
  -h, --help            Show help and exit.

  General:
    These options relate to general matters.

    --verbose           Enable the verbose mode.
    --install           Install 'commix' to your system.
    --version           Show version number and exit.
    --update            Check for updates (apply if any) and exit.
    --output-dir=OUT..  Set custom output directory path.

  Target:
    This options has to be provided, to define the target URL.

    -u URL, --url=URL   Target URL.
    --url-reload        Reload target URL after command execution.
    -l LOGFILE          Parse target and data from HTTP proxy log file.

  Request:
    These options can be used to specify how to connect to the target URL.

    --host=HOST         HTTP Host header.
    --referer=REFERER   HTTP Referer header.
    --user-agent=AGENT  HTTP User-Agent header.
    --random-agent      Use a randomly selected HTTP User-Agent header.
    --param-del=PDEL    Set character for splitting parameter values.
    --cookie=COOKIE     HTTP Cookie header.
    --cookie-del=CDEL   Set character for splitting cookie values.
    --headers=HEADERS   Extra headers (e.g. 'Header1:Value1\nHeader2:Value2').
    --proxy=PROXY       Use a HTTP proxy (e.g. '127.0.0.1:8080').
    --tor               Use the Tor network.
    --tor-port=TOR_P..  Set Tor proxy port (Default: 8118).
    --auth-url=AUTH_..  Login panel URL.
    --auth-data=AUTH..  Login parameters and data.
    --auth-type=AUTH..  HTTP authentication type (e.g. 'basic').
    --auth-cred=AUTH..  HTTP Authentication credentials (e.g. 'admin:admin').

  Enumeration:
    These options can be used to enumerate the target host.

    --current-user      Retrieve current user name.
    --hostname          Retrieve current hostname.
    --is-root           Check if the current user have root privileges.
    --is-admin          Check if the current user have admin privileges.
    --sys-info          Retrieve system information.
    --users             Retrieve system users.
    --passwords         Retrieve system users password hashes.
    --privileges        Retrieve system users privileges.
    --ps-version        Retrieve PowerShell's version number.

  File access:
    These options can be used to access files on the target host.

    --file-read=FILE..  Read a file from the target host.
    --file-write=FIL..  Write to a file on the target host.
    --file-upload=FI..  Upload a file on the target host.
    --file-dest=FILE..  Host's absolute filepath to write and/or upload to.

  Modules:
    These options can be used increase the detection and/or injection
    capabilities.

    --icmp-exfil=IP_..  The 'icmp exfiltration' injection technique
                        (e.g. 'ip_src=192.168.178.1,ip_dst=192.168.178.3').
    --shellshock        The 'shellshock' injection technique.

  Injection:
    These options can be used to specify which parameters to inject and to
    provide custom injection payloads.

    --data=DATA         POST data to inject (use 'INJECT_HERE' tag to specify
                        the testable parameter).
    --suffix=SUFFIX     Injection payload suffix string.
    --prefix=PREFIX     Injection payload prefix string.
    --technique=TECH    Specify injection technique(s) to use.
    --maxlen=MAXLEN     The length of the output on time-based technique
                        (Default: 10000 chars).
    --delay=DELAY       Set Time-delay for time-based and file-based
                        techniques (Default: 1 sec).
    --tmp-path=TMP_P..  Set remote absolute path of temporary files directory
                        (Default: /tmp/).
    --root-dir=SRV_R..  Set remote absolute path of web server's root
                        directory (Default: /var/www/).
    --alter-shell=AL..  Use an alternative os-shell (e.g. Python).
    --os-cmd=OS_CMD     Execute a single operating system command.
    --base64            Encode the operating system command to Base64 format.

Contents

User's manual

Exploitation

Miscellaneous

  • Presentations - Conference talks, demos, and public presentations where commix has been featured or discussed.
  • Screenshots - Visual examples of commix in action
  • Third party references - References to commix in books, articles, research papers, blog posts, etc
  • Command injection testbeds - A curated list of intentionally vulnerable web applications and platforms for safely testing commix

Clone this wiki locally