Reverse Shells

Offensive Reverse Shell (Cheat Sheet)

Collection of reverse shells for red team operations

  • Bash

  • Netcat

    • Netcat Linux

    • Netcat Windows

  • BusyBox

  • cURL

  • Wget

  • Node-RED

  • WebShells

    • Exif Data

    • ASP WebShell

    • PHP WebShell

      • Chain Filter

      • GET

      • POST

    • Log Poisoning WebShell

      • SSH

      • FTP

      • HTTP

  • Server Side Template Injection (SSTI)

  • UnrealIRCd

  • Exif Data

  • Shellshock

    • SSH

    • HTTP

      • HTTP 500 Internal Server Error

  • CMS

    • WordPress

    • October

    • Jenkins

      • Windows

      • Linux

  • Perl

  • Python

  • Python3

  • PHP

  • Ruby

  • Xterm

  • Ncat

  • Socat

  • PowerShell

  • Awk

  • Gawk

  • Golang

  • Telnet

  • Java

  • Node

  • Msfvenom

    • Web Payloads

      • PHP

      • WAR

      • JAR

      • JSP

      • ASPX

    • Linux Payloads

      • Listener Netcat

      • Listener Metasploit Multi Handler

    • Windows Payloads

      • Listener Netcat

      • Listener Metasploit Multi Handler


Bash

TCP

-i

196

read line

5

-c

UDP


Netcat

Netcat Linux

-e

-c

NO -e -c

fifo


Netcat Windows


BusyBox


cURL


Wget


Node-RED


WebShells

Exif Data WebShell

ASP WebShell

PHP WebShell

Chain Filter

http://192.168.1.2/file.php?file="paste chain filter"

GET

POST


Log Poisoning WebShell

Log Poisoning SSH

/var/log/auth.log

/var/log/auth.log&cmd=id


Log Poisoning FTP

/var/log/vsftpd.log

/var/log/vsftpd.log&cmd=id


Log Poisoning HTTP

/var/log/apache2/access.log

/var/log/nginx/access.log

/var/log/apache2/access.log&cmd=id

/var/log/nginx/access.log&cmd=id


Server Side Template Injection


UnrealIRCd


Exif Data Reverse Shell


Shellshock

Shellshock SSH


Shellshock HTTP


Shellshock HTTP 500 Internal Server Error


CMS

WordPress

Create Plugin (Reverse Shell)

Content

Compress

Steps

  • Plugins

  • Add New

  • Upload Plugin

  • Install Now

  • Activate Plugin


October


Jenkins

Jenkins Windows

Netcat (Method 1)

Netcat (Method 2)

CMD

PowerShell

Jenkins Linux

Netcat (Method 1)

Netcat (Method 2)

Bash


Perl


Python

Sh

Bash


Python3

Sh

Bash


PHP


Ruby


Xterm


Ncat

TCP

UDP


Socat


PowerShell


Awk


Gawk


Golang


Telnet


Java


Node


Msfvenom

Web Payloads

PHP Payload

War Payload

JAR Payload

JSP Payload

ASPX Payload


Windows Payloads

Windows Listener Netcat

x86 - Shell

x64 - Shell

Windows Listener Metasploit Multi Handler

x86 - Meterpreter

x64 - Meterpreter

x86 - Shell

x64 - Shell


Linux Payloads

Linux Listener Netcat

x86 - Shell

x64 - Shell


Linux Listener Metasploit Multi Handler

x86 - Meterpreter

x64 - Meterpreter

x86 - Shell

x64 - Shell


Last updated