Basic Syntax
Common Options
| Option | Description |
|---|---|
-p | Payload |
LHOST | Attacker IP |
LPORT | Listening port |
-f | Output format |
-o | Output file |
-e | Encoder |
-i | Encode iterations |
-b | Bad chars |
--platform | Force platform |
-a | Architecture |
🎯 LISTENER (Metasploit)
🪟 Windows Payloads
🖥️ Meterpreter (Recommended)
EXE
Staged HTTPS (Bypass AV better)
DLL (for DLL hijacking)
ASPX (IIS upload)
HTA (phishing / web)
🧾 Normal Shell (cmd)
🧬 Encoded Payload (AV evasion basic)
🐧 Linux Payloads
🧠 Meterpreter ELF
🧾 Normal Bash Shell
🐍 Python Payload
🐚 Bash One-liner
🐘 PHP Webshell Reverse
🌐 WEB PAYLOADS (Useful in Upload Vulns)
| Language | Payload |
|---|---|
| JSP | java/jsp_shell_reverse_tcp |
| WAR | java/jsp_shell_reverse_tcp -f war |
| PHP | php/reverse_php |
| ASP | windows/meterpreter/reverse_tcp -f asp |
| ASPX | windows/meterpreter/reverse_tcp -f aspx |