RCE

Critical

Remote Code Execution

Definition

Remote Code Execution (RCE) is the ability to run arbitrary code on a remote system without physical or prior access to it. It is not a vulnerability in itself, but an impact that can result from multiple types of vulnerabilities such as command injection, SSTI, deserialization, SQLi or SSRF. It is the holy grail of bug bounty for its maximum impact.

Impact

Full compromise of the affected serverAccess to all data stored on the systemPossibility of lateral movement to other internal systemsInstallation of backdoors for persistent accessMaximum reward in bug bounty programs (10k-100k+ EUR)

Examples

Common chains to achieve RCE

The most common chains to achieve RCE in bug bounty include: SSRF → Cloud metadata → Credentials → Access to internal services, SSTI → Template-engine code execution, Deserialization → Gadget chain → System.exec(), LFI → Log poisoning → PHP code inclusion, SQL Injection → xp_cmdshell (MSSQL) or INTO OUTFILE (MySQL).

External references

Practice RCE with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
hunters training
712

hunters training

labs from real reports
55

labs from real reports

completions
1,206

completions

in bounties practiced
$213,970

in bounties practiced

46 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime