Skip to main content

Situational Awareness

Get your bearings immediately after landing a shell: know what you’re on, who you are, and what network you can reach before doing anything else.

Credential Hunting

Config files, shell history, and SSH keys are the highest-yield targets: grep broadly and follow the trail.

File Transfer

Stand up a quick HTTP server on the attacker machine and pull files down with wget or curl: works in almost every environment.
To send files back to the attacker, use uploadserver which adds PUT/POST upload support to the standard Python server.

Shell Upgrade

Raw netcat shells are fragile: upgrade to a full PTY immediately so you get job control, tab completion, and proper signal handling. Try each method in order until one works. After spawning the PTY, always do the stty dance to pass through control characters.
After spawning the PTY:
Get your local terminal dimensions to set them exactly:

Polyshell

polyshell generates a dropper script called rev that tries every available interpreter on the target in sequence (python3 → python2 → bash → perl → php → ruby → socat → nc variants), stopping on the first successful connection. The injected string stays minimal: no spaces, quotes, or redirect operators, so it survives more filter configurations than a raw shell payload. Stand up a listener, generate the dropper and serve it, then inject.
Choose an inject pattern based on what the target filters.
Convert your IP to its decimal equivalent when dots are filtered.

SUID Failures in Reverse Shells

Some privesc paths look valid but silently do nothing through a reverse shell. Two mechanisms cause this. No TTY. A reverse shell is a raw I/O tunnel with no TTY device. SUID binaries, sudo, and PAM-based auth require a proper TTY to grant elevated privileges. Without one, they silently drop the privilege with no error. PR_SET_NO_NEW_PRIVS. If your shell was spawned through a web server like Apache, it likely inherited this kernel flag:
It’s a one-way flag: once set, every child process inherits it and it cannot be unset. The kernel ignores setuid bits and blocks any execve-based privilege gain for the entire lineage. PATH hijacks and SUID binaries both fail silently. Fix: inject your public key into the target user’s ~/.ssh/authorized_keys and SSH in. You get a clean TTY with no inherited restrictions, and the same privesc path that failed before will work.