About this project
Commix (short for command injection exploiter) is an open-source penetration testing tool, written in Python, that automates the detection and exploitation of command injection and code injection vulnerabilities. It is primarily intended as a standalone CLI tool and runs operating system commands on the targets it tests, so it should only be used against systems you own or are explicitly authorised to test.
Key capabilities described in the README:
- Five injection techniques: results-based (classic), boolean-based blind, time-based blind, file-based blind (including a tempfile-based variant for write-restricted targets), and out-of-band (OAST) over HTTP/S and DNS. Techniques can be selected with --technique or filtered by reported type with --type.
- Code injection testing via --eval, which tests the string a target evaluates as code in PHP or Python, using the same techniques.
- Broad injection surface: GET/POST parameters, HTTP headers, cookies, JSON/XML request bodies, plus a shellshock module for CGI targets.
- Interactive shells and post-exploitation: an os_shell on the target, built-in reverse_tcp and bind_tcp modes, file download/upload over the established shell, and enumeration of current user, hostname, privileges, system information, users and password hashes. Findings can be re-proved with --proof, which runs its own experiment and writes a transcript beside the run output.
- Filter and WAF evasion through multiple combinable tamper scripts applied in a deterministic order.
- Flexible targeting: a single URL, a crawl, HTML forms, a sitemap, a proxy log, a bulk file, a raw HTTP request file, or piped stdin.
- Resumable scans and machine-readable output: results are stored per target in a session file and can be exported as JSON, CSV covering every target tested, or a HAR log of the run's HTTP traffic. Run options can be saved as a reusable profile.
- Wide back-end support: PHP, Python, Perl, Ruby, ASP.NET, JSP and CGI, against both Unix-like and Windows targets.
Installation is by cloning the Git repository (or downloading a tarball/zipball); Python 3.7 or later is required and all other dependencies are bundled. Usage examples in the README cover testing a single injectable parameter and dropping into a shell, proving out-of-band execution where the response returns nothing, and scanning a list of targets unattended with batch mode and JSON reporting. Out-of-band detection uses the public oast.fun interactsh server by default, so interaction metadata leaves your network unless --oob-server points at a self-hosted instance. The project is in active development, with breaking changes possible between revisions; documentation, usage examples and filter-bypass examples are available on the project wiki.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.