
commix is an open-source Python CLI that automates detection and exploitation of OS command and code injection flaws, built for authorized penetration tests and bug bounty work.
| Tool | commixproject/commix — automated command injection detection and exploitation framework written in Python |
| Category | web application exploitation / vulnerability scanner |
| Primary Use | Finding and demonstrating command and code injection flaws (--url, --technique, --proof) during authorized pentests and bug bounty engagements |
| Safe Use | Use only against systems you own or have explicit written authorization to test, such as lab testbeds, internal assessments, and sanctioned bug bounty scopes; the README itself warns against unauthorized use |
| Telemetry Note | Generates distinctive HTTP request patterns (time delays, OAST callbacks to oast.fun by default) visible in WAF and server logs; results are also written to session files, JSON/CSV/HAR exports on the operator's machine |
commix, short for command injection exploiter, is one of the longer-lived open-source fixtures in the web application testing space, written and maintained by Anastasios Stasinopoulos under the CommixProject banner. With nearly six thousand stars on GitHub and a pure Python codebase requiring version 3.7 or later, it occupies roughly the same niche for OS command injection that sqlmap occupies for SQL injection: a single CLI that takes a target, probes the injection surface systematically, and then demonstrates impact. The README is unusually candid about its own risk profile — it executes real operating system commands on the targets it tests, warns that running it as a service may pose security risks, and explicitly directs users to operate only against systems they own or are authorized to test. That framing matters, and it frames this article too: commix is a professional's instrument for authorized assessment, not a toy.
The tool's architecture is organized around five injection techniques, selectable with --technique: results-based (the classic case where command output lands in the HTTP response), boolean-based blind (inferring results from page content), time-based blind (inferring from response latency), file-based blind (with a tempfile-based variant for write-restricted targets), and out-of-band detection over HTTP/S and DNS using OAST-style callbacks via --oob. This taxonomy mirrors the classical blind-injection methodology that professionals already know from database exploitation tooling, which makes commix feel familiar to anyone coming from sqlmap. The distinction between --technique (choosing what to run) and --type (filtering what gets reported) is a small but telling design detail — it separates the testing engine from the reporting layer.
Beyond plain command injection, commix also handles code injection through the --eval option, testing whether a target evaluates attacker-controlled strings as code in PHP, Python, Ruby, JavaScript, or PowerShell. This is a meaningfully broader scope than the tool's name suggests, because code injection and command injection are distinct vulnerability classes with different remediations, and a single tool covering both — over the same five-technique framework — reduces the operator's toolchain churn during an engagement. Back-end coverage is correspondingly wide: PHP, Python, Perl, Ruby, ASP.NET, JSP, and CGI, against both Unix-like and Windows targets, with the wiki documenting how payloads differ between the two families.
The injection surface itself is broad. commix probes GET and POST parameters, HTTP headers, cookies, and JSON/XML request bodies, and ships a dedicated shellshock module for CGI targets that are exposed to the classic bash function-export bug. Target acquisition is equally flexible: beyond a single URL, it can crawl a site, parse HTML forms, chew through a sitemap, consume an OpenAPI (Swagger) description, replay entries from a proxy log, read a bulk target file, ingest a raw HTTP request file, or accept piped stdin. The OpenAPI support deserves particular mention — API descriptions enumerate parameters exhaustively, which turns a documentation artifact into a complete injection test plan.
Once a flaw is confirmed, commix pivots into post-exploitation mode. It offers an interactive os_shell on the target, built-in reverse_tcp and bind_tcp modes, file download and upload over the established channel, and enumeration of the current user, hostname, privileges, system information, users, and password hashes. For reporting-grade engagements, --proof re-runs an experiment of its own for every finding and writes the transcript beside the run's output — a genuinely useful touch for consultants who need reproducible evidence rather than a screenshot. All of this functionality should be understood as existing solely for demonstrating impact inside authorized scope, where proving exploitability is the deliverable.
For defenders reading this analytically, the reporting and session machinery is where commix shows its engineering maturity. Results are stored per target in a session file, scans are resumable, and output can be exported as JSON, as a CSV covering every target tested, or as a HAR log of all HTTP traffic generated during the run. Option sets can be saved as profiles and reused, which supports consistent methodology across an engagement — the kind of reproducibility that QA-style security programs value. Batch mode (--batch, -m for a target list, --report-json) enables unattended scanning of large authorized scopes.
Filter and WAF evasion is supported through multiple combinable tamper scripts applied in a deterministic order, and the wiki carries a dedicated filters-bypasses page. From a defensive perspective this is worth knowing in both directions: blue teams should understand that mature tooling automatically retries with obfuscated payloads when a first attempt is blocked, so a WAF block event is a signal to investigate, not a resolution. Conversely, the deterministic tamper ordering means evasion traffic has structure, and the tool's blind techniques — especially time-based delays and OAST DNS callbacks — leave characteristic timing and resolution patterns in logs.
A significant operational caveat sits in the out-of-band feature. By default, --oob uses the public oast.fun interactsh server, which means interaction metadata about the target leaves the operator's network and transits a third-party service. The README is refreshingly explicit about this and recommends pointing --oab-server — actually --oob-server — at a self-hosted instance to keep callbacks in-house. For engagements with data-handling restrictions or strict scope agreements, this default is a compliance landmine, and standing up a private OAST endpoint should be treated as a prerequisite rather than an optimization.
Installation is deliberately minimal, reflecting the project's philosophy of bundling dependencies: clone the repository and run it, with no additional install step. The basic invocation shape is straightforward once inside an authorized environment such as the project's own testbed, for example python3 commix.py --url="hxxp://commix-testbed/..." --os-shell, and python3 commix.py -h enumerates the full option surface. The project is in active development with breaking changes expected between revisions, so consulting the CHANGELOG before updating is the maintainers' own advice.
The project's hygiene signals are strong: continuous integration via GitHub Actions (builds.yml), GPLv3 licensing badges (the repo metadata flags the license as NOASSERTION, suggesting some custom terms in LICENSE.txt worth reading before commercial redistribution), a multi-language README with Greek, Spanish, French, Persian, Indonesian, and Turkish translations, and an active wiki covering usage examples, techniques, and filter bypasses. Topics on the repository — bugbounty, pentesting, detection, vulnerability-scanner — accurately describe its dual audience of offensive testers and the defenders who study such tooling.
Where commix fits in a professional workflow is at the verification and demonstration stage of command injection assessment. Fuzzers and static analyzers flag candidates; commix confirms them with the --proof transcripts that reports need. Its resumable sessions, machine-readable exports, and profile reuse make it suitable for repeatable regression testing of fixed vulnerabilities in CI-adjacent security pipelines — re-running a saved profile after a patch to confirm the injection is genuinely closed is a legitimate and underrated use. Combined with its disciplined scope warnings, that makes commix a tool that rewards careful, authorized operators and punishes careless ones, exactly as an exploitation framework should.
commixproject/commix.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.