PHP Execute Command - Metasploit
This page contains detailed information about how to use the payload/php/exec metasploit module. For list of all metasploit modules, visit the Metasploit Module Library.
Module Overview
Name: PHP Execute Command
Module: payload/php/exec
Source code: modules/payloads/singles/php/exec.rb
Disclosure date: -
Last modification time: 2021-01-05 14:59:46 +0000
Supported architecture(s): php
Supported platform(s): PHP
Target service / protocol: -
Target network port(s): -
List of CVEs: -
Execute a single system command
Module Ranking and Traits
Module Ranking:
- normal: The exploit is otherwise reliable, but depends on a specific version and can't (or doesn't) reliably autodetect. More information about ranking can be found here.
Basic Usage
msf > use payload/php/exec
msf payload(exec) > show options
... show and set options ...
msf payload(exec) > generate
To learn how to generate payload/php/exec with msfvenom, please read this.
Required Options
- CMD: The command string to execute
Go back to menu.
Msfconsole Usage
Here is how the php/exec payload looks in the msfconsole:
msf6 > use payload/php/exec
msf6 payload(php/exec) > show info
Name: PHP Execute Command
Module: payload/php/exec
Platform: PHP
Arch: php
Needs Admin: No
Total size: 1315
Rank: Normal
Provided by:
egypt <[email protected]>
Basic options:
Name Current Setting Required Description
---- --------------- -------- -----------
CMD yes The command string to execute
Description:
Execute a single system command
Module Options
This is a complete list of options available in the php/exec payload:
msf6 payload(php/exec) > show options
Module options (payload/php/exec):
Name Current Setting Required Description
---- --------------- -------- -----------
CMD yes The command string to execute
Advanced Options
Here is a complete list of advanced options supported by the php/exec payload:
msf6 payload(php/exec) > show advanced
Module advanced options (payload/php/exec):
Name Current Setting Required Description
---- --------------- -------- -----------
VERBOSE false no Enable detailed status messages
WORKSPACE no Specify the workspace for this module
Go back to menu.
Related Pull Requests
- #14584 Merged Pull Request: Implement the zeitwerk autoloader within lib/msf/base
- #14202 Merged Pull Request: Implement the zeitwerk autoloader within lib/msf/core
- #10997 Merged Pull Request: Remove harmful default command to execute
- #8716 Merged Pull Request: Print_Status -> Print_Good (And OCD bits 'n bobs)
- #8338 Merged Pull Request: Fix msf/core and self.class msftidy warnings
- #7904 Merged Pull Request: Fix a bug where PHP tags were in the wrong place
- #6655 Merged Pull Request: use MetasploitModule as a class name
- #4894 Merged Pull Request: Implement payload size caching, speeding up framework loads
- #2525 Merged Pull Request: Change module boilerplate
- #1241 Merged Pull Request: Removed all $Id$ and $Revision$ occurences
Go back to menu.
See Also
Check also the following modules related to this module:
- payload/php/bind_perl
- payload/php/bind_perl_ipv6
- payload/php/bind_php
- payload/php/bind_php_ipv6
- payload/php/download_exec
- payload/php/meterpreter/bind_tcp
- payload/php/meterpreter/bind_tcp_ipv6
- payload/php/meterpreter/bind_tcp_ipv6_uuid
- payload/php/meterpreter/bind_tcp_uuid
- payload/php/meterpreter/reverse_tcp
- payload/php/meterpreter_reverse_tcp
- payload/php/meterpreter/reverse_tcp_uuid
- payload/php/reverse_perl
- payload/php/reverse_php
- payload/php/shell_findsock
Authors
- egypt
Version
This page has been produced using Metasploit Framework version 6.1.24-dev. For more modules, visit the Metasploit Module Library.
Go back to menu.