#reverseshell — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #reverseshell, aggregated by home.social.
-
Sequence [TryHackMe] [Writeup]
Room Info Name: Sequence Platform: TryHackMe Difficulty: Medium Link: https://tryhackme.com/room/sequence Description: Chain multiple vulnerabilities to take control of a system. Task 1: Challenge Robert made some last-minute updates to the review.thm website before heading off on vacation. He claims that the secret information of the financiers is fully protected. But are his defenses truly airtight? Your challenge is to exploit the vulnerabilities and gain complete control of the […]https://aredopseagle.wordpress.com/2026/03/15/sequence-tryhackme-writeup/
-
New CTF walkthrough for TryHackMe's RootMe. This is a fun one!
I just published RootMe (CTF Walkthrough) https://medium.com/p/rootme-ctf-walkthrough-efe69ef73510?source=social.tw
#TryHackMe #Cybersecurity #ReverseShell #CTF #PenetrationTesting
-
New CTF walkthrough for TryHackMe's RootMe. This is a fun one!
I just published RootMe (CTF Walkthrough) https://medium.com/p/rootme-ctf-walkthrough-efe69ef73510?source=social.tw
#TryHackMe #Cybersecurity #ReverseShell #CTF #PenetrationTesting
-
Hiding your callback through HTTPS
https://anonsys.net/display/bf69967c-1868-fce9-5e30-613967945901
-
Hiding your callback through HTTPS
https://anonsys.net/display/bf69967c-1868-fce9-5e30-613967945901
-
Hiding your callback through HTTPS
https://anonsys.net/display/bf69967c-1868-fce9-5e30-613967945901
-
Used #girsh today for the first time with a #HTB box. It is a listener for a reverse shell spawning a fully interactive shell automatically. Worked quite well. I must say, I do miss autocomplete if it is not available.
I did not do a code review of this tool as I was only using it on an isolated VM. Run at your own risk ;)
-
Used #girsh today for the first time with a #HTB box. It is a listener for a reverse shell spawning a fully interactive shell automatically. Worked quite well. I must say, I do miss autocomplete if it is not available.
I did not do a code review of this tool as I was only using it on an isolated VM. Run at your own risk ;)
-
Used #girsh today for the first time with a #HTB box. It is a listener for a reverse shell spawning a fully interactive shell automatically. Worked quite well. I must say, I do miss autocomplete if it is not available.
I did not do a code review of this tool as I was only using it on an isolated VM. Run at your own risk ;)
-
Used #girsh today for the first time with a #HTB box. It is a listener for a reverse shell spawning a fully interactive shell automatically. Worked quite well. I must say, I do miss autocomplete if it is not available.
I did not do a code review of this tool as I was only using it on an isolated VM. Run at your own risk ;)
-
Malware found on NPM infecting local package with reverse shell
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
#HackerNews #Malware #NPM #ReverseShell #CyberSecurity #SoftwareDevelopment
-
Malware found on NPM infecting local package with reverse shell
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
#HackerNews #Malware #NPM #ReverseShell #CyberSecurity #SoftwareDevelopment
-
Malware found on NPM infecting local package with reverse shell
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
#HackerNews #Malware #NPM #ReverseShell #CyberSecurity #SoftwareDevelopment
-
Malware found on NPM infecting local package with reverse shell
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
#HackerNews #Malware #NPM #ReverseShell #CyberSecurity #SoftwareDevelopment
-
Hacker in Snowflake Extortions May Be a U.S. Soldier https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/ #Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Verizon #Boxfan #ShiBot #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/ #Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Verizon #Boxfan #ShiBot #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/ #Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Verizon #Boxfan #ShiBot #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier
https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/
#Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Shi-Bot #Verizon #Boxfan #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier
https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/
#Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Shi-Bot #Verizon #Boxfan #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier
https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/
#Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Shi-Bot #Verizon #Boxfan #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier
https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/
#Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Shi-Bot #Verizon #Boxfan #Naver #Waifu #ATT
-
Hacker in Snowflake Extortions May Be a U.S. Soldier
https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/
#Ne'er-Do-WellNews #ConnorRileyMoucka #telekomterrorist #ALittleSunshine #TheComingStorm #DDoS-for-Hire #JohnErinBinns #cyb3rph4nt0m #Kiberphant0m #Reverseshell #Ransomware #SouthKorea #buttholio #Proman557 #Snowflake #Vars_Secc #Judische #Shi-Bot #Verizon #Boxfan #Naver #Waifu #ATT
-
Mon dieu - Penelope is alright! Probably my favorite #reverseshell catcher for #linux targets. https://github.com/brightio/penelope
Highly recommend!
-
Mon dieu - Penelope is alright! Probably my favorite #reverseshell catcher for #linux targets. https://github.com/brightio/penelope
Highly recommend!
-
Mon dieu - Penelope is alright! Probably my favorite #reverseshell catcher for #linux targets. https://github.com/brightio/penelope
Highly recommend!
-
Mon dieu - Penelope is alright! Probably my favorite #reverseshell catcher for #linux targets. https://github.com/brightio/penelope
Highly recommend!
-
Mon dieu - Penelope is alright! Probably my favorite #reverseshell catcher for #linux targets. https://github.com/brightio/penelope
Highly recommend!
-
Chinese APT Abuses VSCode to Target Government in Asia
[TR: Wait what? VSCode has a reverse shell feature?! Turn this off. Sounds like something proposed by another large company’s dev team recently.] #devtools #reverseshell #c2
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
-
Chinese APT Abuses VSCode to Target Government in Asia
[TR: Wait what? VSCode has a reverse shell feature?! Turn this off. Sounds like something proposed by another large company’s dev team recently.] #devtools #reverseshell #c2
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
-
Chinese APT Abuses VSCode to Target Government in Asia
[TR: Wait what? VSCode has a reverse shell feature?! Turn this off. Sounds like something proposed by another large company’s dev team recently.] #devtools #reverseshell #c2
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
-
Chinese APT Abuses VSCode to Target Government in Asia
[TR: Wait what? VSCode has a reverse shell feature?! Turn this off. Sounds like something proposed by another large company’s dev team recently.] #devtools #reverseshell #c2
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
-
Chinese APT Abuses VSCode to Target Government in Asia
[TR: Wait what? VSCode has a reverse shell feature?! Turn this off. Sounds like something proposed by another large company’s dev team recently.] #devtools #reverseshell #c2
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
-
Why ara #poc for #vulnerability always #reverseshell ? I get that a reverse shell via RCE is a scary magic trick. But in practical #pentesting more often than not I'd rather have a single fire DNS lookup or HTTP request. It's much saver than dropping a shell into a customers environment and it does the job.
-
Hello!
I wanted to share 2 reverse shells I have made in C, for both Windows and Linux! It's only the source codes of them, non-compiled that is.They are made with being as short as possible in mind, so they are not "fancy" in any way.
Contributions is ofc welcome! Reach out to me if you have any questions.
Have a nice day! I will leave the link to the GitHub Repo below.- https://github.com/loneicewolf/ReverseShells
*Hopefully they are useful :tuturu:
-
Hello!
I wanted to share 2 reverse shells I have made in C, for both Windows and Linux! It's only the source codes of them, non-compiled that is.They are made with being as short as possible in mind, so they are not "fancy" in any way.
Contributions is ofc welcome! Reach out to me if you have any questions.
Have a nice day! I will leave the link to the GitHub Repo below.- https://github.com/loneicewolf/ReverseShells
*Hopefully they are useful :tuturu:
-
Hello!
I wanted to share 2 reverse shells I have made in C, for both Windows and Linux! It's only the source codes of them, non-compiled that is.They are made with being as short as possible in mind, so they are not "fancy" in any way.
Contributions is ofc welcome! Reach out to me if you have any questions.
Have a nice day! I will leave the link to the GitHub Repo below.- https://github.com/loneicewolf/ReverseShells
*Hopefully they are useful :tuturu:
-
Hello!
I wanted to share 2 reverse shells I have made in C, for both Windows and Linux! It's only the source codes of them, non-compiled that is.They are made with being as short as possible in mind, so they are not "fancy" in any way.
Contributions is ofc welcome! Reach out to me if you have any questions.
Have a nice day! I will leave the link to the GitHub Repo below.- https://github.com/loneicewolf/ReverseShells
*Hopefully they are useful :tuturu:
-
Hello!
I wanted to share 2 reverse shells I have made in C, for both Windows and Linux! It's only the source codes of them, non-compiled that is.They are made with being as short as possible in mind, so they are not "fancy" in any way.
Contributions is ofc welcome! Reach out to me if you have any questions.
Have a nice day! I will leave the link to the GitHub Repo below.- https://github.com/loneicewolf/ReverseShells
*Hopefully they are useful :tuturu:
-
SaturdayMP Show #18: Hack the Box - Busqueda Part 2 (Reverse Shell)
In this episode I get a reverse shell working and make some progress on capturing the root flag.
Question you want answered in a future video? Pair on a problem? Constructive feedback? DM me or email [email protected].
#hackthebox #cybersecurity #reverseshell #saturdaymp #saturdaympshow
-
SaturdayMP Show #18: Hack the Box - Busqueda Part 2 (Reverse Shell)
In this episode I get a reverse shell working and make some progress on capturing the root flag.
Question you want answered in a future video? Pair on a problem? Constructive feedback? DM me or email [email protected].
#hackthebox #cybersecurity #reverseshell #saturdaymp #saturdaympshow
-
I had a command injection vulnerability, but the target system didn't have netcat or other (obvious) means of getting a reverse shell. What to do? I wrote a minuscule "nc -e /bin/sh" in C + mips assembly, then wrote a small JavaScript stager that would encode the binary to a "echo -ne 'payload'" command that would then be used to drop the binary to /tmp, chmod it and execute with desired ip address and port. The nanonc tool https://sintonen.fi/src/nanonc/ supports both listen and connect back modes. The code calls linux kernel directly, doesn't use libc at all and has a custom startup code. The (low effort) stripped mipsel binary was 1372 bytes. I'm sure it could be made way way smaller, but this was well within reason already.
Was this total overkill and wholly unnecessary amount of work just to exploit this vulnerability? Yes. Did I learn a lot about mips platform, mips calling conventions and how to create tiny apps calling the linux kernel directly? Oh yes. #infosec #hacking #exploitation #tooling #reverseshell
-
I had a command injection vulnerability, but the target system didn't have netcat or other (obvious) means of getting a reverse shell. What to do? I wrote a minuscule "nc -e /bin/sh" in C + mips assembly, then wrote a small JavaScript stager that would encode the binary to a "echo -ne 'payload'" command that would then be used to drop the binary to /tmp, chmod it and execute with desired ip address and port. The nanonc tool https://sintonen.fi/src/nanonc/ supports both listen and connect back modes. The code calls linux kernel directly, doesn't use libc at all and has a custom startup code. The (low effort) stripped mipsel binary was 1372 bytes. I'm sure it could be made way way smaller, but this was well within reason already.
Was this total overkill and wholly unnecessary amount of work just to exploit this vulnerability? Yes. Did I learn a lot about mips platform, mips calling conventions and how to create tiny apps calling the linux kernel directly? Oh yes. #infosec #hacking #exploitation #tooling #reverseshell
-
I had a command injection vulnerability, but the target system didn't have netcat or other (obvious) means of getting a reverse shell. What to do? I wrote a minuscule "nc -e /bin/sh" in C + mips assembly, then wrote a small JavaScript stager that would encode the binary to a "echo -ne 'payload'" command that would then be used to drop the binary to /tmp, chmod it and execute with desired ip address and port. The nanonc tool https://sintonen.fi/src/nanonc/ supports both listen and connect back modes. The code calls linux kernel directly, doesn't use libc at all and has a custom startup code. The (low effort) stripped mipsel binary was 1372 bytes. I'm sure it could be made way way smaller, but this was well within reason already.
Was this total overkill and wholly unnecessary amount of work just to exploit this vulnerability? Yes. Did I learn a lot about mips platform, mips calling conventions and how to create tiny apps calling the linux kernel directly? Oh yes. #infosec #hacking #exploitation #tooling #reverseshell
-
I had a command injection vulnerability, but the target system didn't have netcat or other (obvious) means of getting a reverse shell. What to do? I wrote a minuscule "nc -e /bin/sh" in C + mips assembly, then wrote a small JavaScript stager that would encode the binary to a "echo -ne 'payload'" command that would then be used to drop the binary to /tmp, chmod it and execute with desired ip address and port. The nanonc tool https://sintonen.fi/src/nanonc/ supports both listen and connect back modes. The code calls linux kernel directly, doesn't use libc at all and has a custom startup code. The (low effort) stripped mipsel binary was 1372 bytes. I'm sure it could be made way way smaller, but this was well within reason already.
Was this total overkill and wholly unnecessary amount of work just to exploit this vulnerability? Yes. Did I learn a lot about mips platform, mips calling conventions and how to create tiny apps calling the linux kernel directly? Oh yes. #infosec #hacking #exploitation #tooling #reverseshell
-
I had a command injection vulnerability, but the target system didn't have netcat or other (obvious) means of getting a reverse shell. What to do? I wrote a minuscule "nc -e /bin/sh" in C + mips assembly, then wrote a small JavaScript stager that would encode the binary to a "echo -ne 'payload'" command that would then be used to drop the binary to /tmp, chmod it and execute with desired ip address and port. The nanonc tool https://sintonen.fi/src/nanonc/ supports both listen and connect back modes. The code calls linux kernel directly, doesn't use libc at all and has a custom startup code. The (low effort) stripped mipsel binary was 1372 bytes. I'm sure it could be made way way smaller, but this was well within reason already.
Was this total overkill and wholly unnecessary amount of work just to exploit this vulnerability? Yes. Did I learn a lot about mips platform, mips calling conventions and how to create tiny apps calling the linux kernel directly? Oh yes. #infosec #hacking #exploitation #tooling #reverseshell
-
Controlling your server with a reverse shell attack https://t.co/65HlGDRf9T
#reverseShell #remoteCodeExecution #RCE #security #devsecops https://t.co/LqKB3vOawI -
Controlling your server with a reverse shell attack https://t.co/65HlGDRf9T
#reverseShell #remoteCodeExecution #RCE #security #devsecops https://t.co/LqKB3vOawI -
Controlling your server with a reverse shell attack https://t.co/65HlGDRf9T
#reverseShell #remoteCodeExecution #RCE #security #devsecops https://t.co/LqKB3vOawI -
Controlling your server with a reverse shell attack https://t.co/65HlGDRf9T
#reverseShell #remoteCodeExecution #RCE #security #devsecops https://t.co/LqKB3vOawI -
Controlling your server with a reverse shell attack https://t.co/65HlGDRf9T
#reverseShell #remoteCodeExecution #RCE #security #devsecops https://t.co/LqKB3vOawI