📑 Table of Contents

Shell shoveling, in network security, is the act of redirecting the input and output of a shell to a service so that it can be remotely accessed, a remote shell.[1]

In computing, the most basic method of interfacing with the operating system is the shell. On Microsoft Windows based systems, this is a program called cmd.exe or COMMAND.COM. On Unix or Unix-like systems, it may be any of a variety of programs such as bash, ksh, etc. This program accepts commands typed from a prompt and executes them, usually in real time, displaying the results to what is referred to as standard output, usually a monitor or screen.

In the shell shoveling process, one of these programs is set to run (perhaps silently or without notifying someone observing the computer) accepting input from a remote system and redirecting output to the same remote system; therefore the operator of the shoveled shell is able to operate the computer as if they were present at the console.[2]

See also

edit

References

edit
  1. ^ McClure, Stuart; Scambray, Joel (2000-03-20). "'Inside-out' security pays attention to your revealing, vulnerable outbound traffic". Platforms & Infrastructure. InfoWorld. Vol. 22, no. 12. IDG. p. 49. Retrieved 2023-10-05.
  2. ^ Tipton, Harold "Hal" F.; Krause, Micki (2007). Information Security Management Handbook (6 ed.). CRC Press. p. 2839. ISBN 978-1-4200-1358-0.

Further reading

edit

📚 Artikel Terkait di Wikipedia

Unix shell

Restricted shell Shell account – User account on a remote server Shell script – Script written for an operating system shell Shell shoveling – Computer

Serial over LAN

Emergency Management Services Intelligent Platform Management Interface Shell shoveling Virtual COM port Sys Admin: The Journal for UNIX System Administrators

Virtual COM port

over LAN Emergency Management Services (EMS) IPMI LAN Proxy server Shell shoveling "Null-modem emulator (com0com) - virtual serial port driver for Windows"

Headless computer

(EMS) Serial over LAN (SOL) Console redirection CTTY (DOS command) Shell shoveling Keyboard computer "Overview - HP Integrated Lights-Out". Hewlett-Packard

Redirection (computing)

Here-document, a way of specifying text for input in command-line shells Shell shoveling Command substitution Process substitution Console redirection Feiertag

Shellcode

testing toolPages displaying short descriptions of redirect targets Shell shoveling – Computer network security concept Stack buffer overflow – Software

Emergency Management Services

NTLDR Serial-over-LAN (SOL) Console redirection CTTY (DOS command) Shell shoveling IBM Redbooks Technote Enabling Serial Over LAN for a Remote Windows

Shovel hook

deliver force underneath an opponent's defensive shell. The primary anatomical target of the shovel hook is the solar plexus, jaw, or the liver. Its upward