htshells
Self contained htaccess shells and attacks
Platforms: Linux · Last verified September 6, 2026
htshells is a series of web based attacks based around the .htaccess files. Most of the attacks are centered around two attack categories. Remote code/ command execution and information disclosure. These attacks are intended for use during penetration tests or security assessments. It was created to get shell in a CMS that restricted uploads based on extension and placed each uploaded file in it’s own directory.
Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.
Getting started
Install on Kali Linux with `sudo apt install htshells`. See the official Kali tool page and upstream homepage linked above for full usage and configuration details.