RCE

Critical

Remote Code Execution

Definition

Remote Code Execution (RCE) is the ability to run arbitrary code on a remote system without physical or prior access to it. It is not a vulnerability in itself, but an impact that can result from multiple types of vulnerabilities such as command injection, SSTI, deserialization, SQLi or SSRF. It is the holy grail of bug bounty for its maximum impact.

Impact

Full compromise of the affected serverAccess to all data stored on the systemPossibility of lateral movement to other internal systemsInstallation of backdoors for persistent accessMaximum reward in bug bounty programs (10k-100k+ EUR)

Examples

Common chains to achieve RCE

The most common chains to achieve RCE in bug bounty include: SSRF → Cloud metadata → Credentials → Access to internal services, SSTI → Template-engine code execution, Deserialization → Gadget chain → System.exec(), LFI → Log poisoning → PHP code inclusion, SQL Injection → xp_cmdshell (MSSQL) or INTO OUTFILE (MySQL).

External references

Practice RCE with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime