Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

These are exploits created to avoid the use of Metasploit. While studying for OSCP in the Offsec labs, VHL, Vulnhub, etc, I tried to find ways to limit my use of Metasploit and Meterpreter shells.

Notifications You must be signed in to change notification settings

blu0/webdav-exploit

Open more actions menu

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
14 Commits
 
 
 
 
 
 

Repository files navigation

🛠️ WebDAV Exploits (No Metasploit / No Meterpreter)

These are simple WebDAV-based exploits created to avoid the use of Metasploit and Meterpreter shells.
They were developed during OSCP preparation and tested against targets in OffSec labs, VHL, VulnHub, and similar environments.


📄 Overview

The goal of these tools is to explore alternative post-exploitation methods in constrained environments, or in labs where Metasploit is discouraged or restricted.


🔧 Exploit Scripts

1. webdavrev.py

  • Uploads a PHP reverse shell for Windows
  • Establishes a basic shell back to the attacker's machine
  • Useful when a remote shell is achievable via HTTP PUT

Includes a PHP payload adapted for reverse connectivity.


2. webdavbd.py

  • Drops a CMD backdoor on the target
  • No automatic shell; useful in cases where reverse shells are unstable or blocked
  • Ideal fallback when the target is partially responsive

⚠️ Legal Notice

These scripts are provided for educational and authorized testing purposes only.

Do not use these tools on any system unless you have explicit permission to do so.
Unauthorized use is illegal and unethical.


💡 Use Case

  • OSCP or CTF-style environments
  • Situations with no Metasploit allowance
  • Learning custom shell delivery or backdoor placement

About

These are exploits created to avoid the use of Metasploit. While studying for OSCP in the Offsec labs, VHL, Vulnhub, etc, I tried to find ways to limit my use of Metasploit and Meterpreter shells.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

Morty Proxy This is a proxified and sanitized view of the page, visit original site.