How is a reverse shell used in practice?

Hi,

I am following the Tryhackme Jr Penetration Tester course. I just completed the Metasploit Exploitation chapter which shows you how to use mfsvenom.

It explains how to create a reverse shell in different languages, SSH into the remote machine, download the reverse shell and execute it as root. However it is unclear to me how this is used in the ‘real’ world? In the real world I don’t have access to a machine with sudo permissions so I can upload a file, because if I would why would I upload a reverse shell script? Or is it used where I have been able to exploit a service, have a shell, upload a script as a ‘backdoor’ to get back in, if the software gets patched?

Thank you!

submitted by /u/Ramshield
[link] [comments]

July 16, 2023
Read More >>