module
Windows Command Shell, Hidden Bind TCP Inline
| Disclosed | Created |
|---|---|
| N/A | May 30, 2018 |
Disclosed
N/A
Created
May 30, 2018
Description
Listen for a connection from certain IP and spawn a command shell.
The shellcode will reply with a RST packet if the connections is not
coming from the IP defined in AHOST. This way the port will appear
as "closed" helping us to hide the shellcode.
The shellcode will reply with a RST packet if the connections is not
coming from the IP defined in AHOST. This way the port will appear
as "closed" helping us to hide the shellcode.
Authors
Platform
Windows
Architectures
x86
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.