3 ms·
There's one point I do not understand. After running this, you always need the ip of the victim to remote login, correct? or there's something I missed?
by bigd 13y ago
There's one point I do not understand. After running this, you always need the ip of the victim to remote login, correct? or there's something I missed?
- jstanley 13y agoThe script connects to your server. You open a listening socket on your server, then when the client connects it presents a shell.
- bigd 13y agoI see, but Isn't that a risk for the attacker? I taught the idea was to run a server on the victim and connect to it... In my mind the script was supposed to post the victim ip on pastebin. There's something wrong with my approach? any good resource to understand the logic?
- jstanley 13y agoHow is it a risk to the attacker? The attacker isn't presenting a shell on his server, the client is the one presenting the shell. You could just as well post the IP address somewhere and connect later, but then you have to worry about escaping NAT. I don't really know what resources would help, possibly the netcat man page? http://linux.die.net/man/1/nc http://linux.die.net/man/1/nc
- bigd 13y agosince you are statically sharing the server details... Isn't this as leaving your id card on the crime scene? anyway, for who might be interested, the technical term is "reverse shell" (the one in the article) or "bind shell" (the one I wanted).