SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • 🚀 Start Here Beginner path through the site
  • 🗺️ Penetration Testing Roadmap Structured path to become a pentester
  • 🎓 Free Security Courses Current free Udemy coupon listings
  • 📄 Secure Code Explain Vulnerable vs secure code side by side
  • 🎯 Penetration Testing Tricks Field notes for real engagements
  • 📖 Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • ✅ Security Checklists Hub All interactive security checklists
  • 📋 Writeup Checklists Steps derived from real writeups
  • 🧠 LLM AI Security Checklist Controls for LLM apps
  • 🤖 OWASP LLM Top 10 LLM Top 10 risks mapped out
  • 🧰 Burp Suite Guide Step-by-step Burp tutorials
  • 📘 Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • 🔬 Interactive Labs SQL injection, AI, architecture review
  • 🎮 Security Games Phishing, JWT, WAF, and more
  • 🚗 On-Call Drive Neon-city arcade security missions
  • • Shift Zero SOC desk: phish, OTP, malware, tickets
  • ❓ Application Security Quiz Web, secure coding, and cloud quizzes
  • 🗺️ OWASP Top 10 Explorer Clickable risk map with signals
  • 🔀 Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • 🛠️ Security Tools Curated recon, SAST, and bounty tools
  • 🔎 CVE Lookup Multi-source CVE intelligence
  • 💰 Bug Bounty Programs Live public scopes to search
  • 💼 Cybersecurity Jobs Roles from company career pages
  • 🧑‍💻 Security Researchers Community profiles and submissions
  • 🎤 Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security →
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile →
← Security Tools View on GitHub

commix

Automated All-in-One OS command injection and exploitation tool.

CommixProject

English • Ελληνικά • Español • Français • فارسی • Bahasa Indonesia • Türkçe

Builds Tests Python 3.7+ GPLv3 License Follow @commixproject

Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command (and code) injection vulnerabilities.

Screenshot

You can visit the collection of screenshots demonstrating some of the features on the wiki.

[!IMPORTANT] This project is in active development. Expect breaking changes between revisions. Review the changelog before updating.

Commix is primarily built to be used as a standalone CLI tool, and it executes operating system commands on the targets it tests. Running commix as a service may pose security risks.

It is recommended to use it with caution, and only against systems you own or have explicit authorisation to test.

Features

  • Four injection techniques - results-based (classic), boolean-based (blind, reading the answer off the page), time-based (blind), and file-based (blind, with a tempfile-based variant for write-restricted targets). Selected with --technique, or by the type they report with --type. Plus an out-of-band (OAST) channel over HTTP/S and DNS, turned on with its own --oob switch rather than a --technique of its own.
  • Code injection - --eval tests the string a target evaluates as code, in PHP, Python, Ruby, JavaScript or PowerShell, over the same four techniques (and the out-of-band channel).
  • Broad injection surface - GET/POST parameters, HTTP headers, cookies, and JSON/XML request bodies, plus the shellshock module for CGI targets.
  • Interactive shells and post-exploitation - an os_shell on the target, built-in reverse_tcp and bind_tcp modes, file download/upload over the established shell, and enumeration of the current user, hostname, privileges, system information, users and password hashes. Every finding can be re-proved with --proof, which runs an experiment of its own and writes the transcript beside the run's output.
  • Filter and WAF evasion - Multiple combinable tamper scripts, applied in a deterministic order.
  • Flexible targeting - a single URL, a crawl, HTML forms, a sitemap, an OpenAPI (Swagger) description, a proxy log, a bulk file, a raw HTTP request file, or piped stdin.
  • Resumable scans and machine-readable output - results are stored per target in a session file, and can be exported as JSON, as a CSV covering every target tested, or as a HAR log of the run's HTTP traffic. The options a run was given can be saved as a profile and reused.
  • Wide back-end support - PHP, Python, Perl, Ruby, ASP.NET, JSP and CGI, and works against both Unix-like and Windows targets - see Windows and Unix-like targets at a glance for how the payloads differ.

Installation

You can download commix on any platform by cloning the official Git repository :

$ git clone https://github.com/commixproject/commix.git commix

Alternatively, you can download the latest tarball or zipball.

[!NOTE] Python (version 3.7 or later) is required for running commix. All other dependencies are bundled, so no additional installation step is needed.

Usage

To get a list of all options and switches use:

$ python3 commix.py -h

Test a single injectable parameter, then drop into a shell on the target :

$ python3 commix.py --url="http://commix-testbed/scenarios/regular/GET/classic.php?addr=127.0.0.1" --os-shell

Prove execution out-of-band, where the response carries nothing back :

$ python3 commix.py --url="http://commix-testbed/scenarios/regular/POST/blind.php" --data="addr=127.0.0.1" --oob

[!NOTE] Out-of-band (OAST) detection with --oob uses the public oast.fun interactsh server by default, so interaction metadata for your target leaves your network. Point --oob-server at a self-hosted instance to keep it in-house. For a detailed guide, refer to the out-of-band-oob-channel wiki page.

Scan a list of targets unattended and write the results to a file :

$ python3 commix.py -m targets.txt --batch --report-json=results.json

To get an overview of commix available options, switches and/or basic ideas on how to use commix, check usage, usage examples and filters bypasses wiki pages.

Links

  • User's manual: https://github.com/commixproject/commix/wiki
  • Issues tracker: https://github.com/commixproject/commix/issues
Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 Security Cipher. All rights reserved. Privacy Policy · Terms & Conditions