{"id":51952289,"url":"https://github.com/benjitrapp/raccshells","last_synced_at":"2026-07-29T07:00:57.273Z","repository":{"id":368397663,"uuid":"1283925586","full_name":"BenjiTrapp/RaccShells","owner":"BenjiTrapp","description":"🦝 Self-contained reverse shell generator — zero dependencies, single HTML file. Syntax highlighting, animated diagrams, shell obfuscation, LotL techniques \u0026 more.","archived":false,"fork":false,"pushed_at":"2026-06-30T10:37:52.000Z","size":197,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-30T12:23:07.161Z","etag":null,"topics":["bind-shell","lolbas","msfvenom","obfuscation","offensive-security","payload-generator","penetration-testing","red-team","reverse-shell","reverse-shell-generator","shell-generator"],"latest_commit_sha":null,"homepage":"https://benjitrapp.github.io/RaccShells/","language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BenjiTrapp.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-29T11:10:11.000Z","updated_at":"2026-06-30T10:37:56.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/BenjiTrapp/RaccShells","commit_stats":null,"previous_names":["benjitrapp/raccshells"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/BenjiTrapp/RaccShells","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FRaccShells","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FRaccShells/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FRaccShells/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FRaccShells/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BenjiTrapp","download_url":"https://codeload.github.com/BenjiTrapp/RaccShells/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FRaccShells/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36022278,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-29T02:00:04.910Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bind-shell","lolbas","msfvenom","obfuscation","offensive-security","payload-generator","penetration-testing","red-team","reverse-shell","reverse-shell-generator","shell-generator"],"created_at":"2026-07-29T07:00:56.322Z","updated_at":"2026-07-29T07:00:57.266Z","avatar_url":"https://github.com/BenjiTrapp.png","language":"HTML","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"static/raccshell_transparent.png\" alt=\"RaccShells Logo\" height=\"180\"/\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eRaccShells\u003c/h1\u003e\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eSelf-contained reverse shell generator · zero dependencies · single HTML file\u003c/strong\u003e\u003cbr/\u003e\n  \u003csub\u003eFor authorised penetration testing and CTF use only\u003c/sub\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/shells-111-00ff00?style=flat-square\u0026labelColor=0a0a0a\u0026color=00cc00\"/\u003e\n  \u003cimg src=\"https://img.shields.io/badge/platform-any%20browser-00ff00?style=flat-square\u0026labelColor=0a0a0a\u0026color=00cc00\"/\u003e\n  \u003cimg src=\"https://img.shields.io/badge/dependencies-zero-00ff00?style=flat-square\u0026labelColor=0a0a0a\u0026color=00cc00\"/\u003e\n  \u003cimg src=\"https://img.shields.io/badge/license-MIT-00ff00?style=flat-square\u0026labelColor=0a0a0a\u0026color=00cc00\"/\u003e\n\u003c/p\u003e\n\n---\n\n## What is it?\n\nRaccShells is a **self-contained, single-file** reverse shell reference tool. Open `index.html` — no server, no install, no internet required. Enter your IP and port, copy the shell, and go.\n\nBuilt with a dark terminal aesthetic: scanline overlay, matrix green, monospace everything.\n\n---\n\n## Feature Overview\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"static/mockup.svg\" alt=\"RaccShells UI Mockup\" width=\"100%\"/\u003e\n\u003c/p\u003e\n\n| Tab | Contents |\n|-----|----------|\n| **Reverse Shells** | 72 shells across Bash, Python, Perl, PHP, Ruby, PowerShell, Java, Go, Lua, Awk, … |\n| **Bind Shells** | 14 bind-side listeners |\n| **MSFVenom** | 25 ready-to-paste msfvenom payloads |\n| **Shell Upgrade** | TTY spawn, stty raw, socat fully interactive, escape binaries |\n| **Tools \u0026 Listeners** | pwncat-cs, pwncat (cytopia), Chashell, HellShell, SSL-AES, FuegoShell, CHAOS RAT, tmate |\n| **Living off the Land** | Windows (LOLBAS) + Linux + macOS — download, exec, persistence, tunnel |\n\n---\n\n## Traffic Flow Diagrams\n\nEvery shell shows an animated SVG diagram when expanded — no static images, generated inline.\n\n```mermaid\nflowchart LR\n    subgraph VICTIM\n        V[\"💻 :random\"]\n    end\n    subgraph ATTACKER\n        A[\"🖥 :4444 LISTEN\"]\n    end\n\n    V -- \"① TCP connect-back\" --\u003e A\n    A -. \"② commands\" .-\u003e V\n    V -. \"③ output\" .-\u003e A\n```\n\n```mermaid\nflowchart LR\n    subgraph ATTACKER\n        A[\"🖥 connects\"]\n    end\n    subgraph VICTIM\n        V[\"💻 :4444 LISTEN\"]\n    end\n\n    A -- \"① connect to port\" --\u003e V\n    A -. \"② commands\" .-\u003e V\n    V -. \"③ output\" .-\u003e A\n```\n\n```mermaid\nflowchart LR\n    subgraph VICTIM\n        V[\"💻 DNS client\"]\n    end\n    subgraph DNS[\"DNS Nameserver\\nyour domain NS\"]\n        D[\" \"]\n    end\n    subgraph ATTACKER\n        A[\"🖥 NS record\"]\n    end\n\n    V -- \"① DNS query\\n(XSalsa20 enc)\" --\u003e D\n    D -- \"NS forward\" --\u003e A\n    A -. \"② encoded response\" .-\u003e D\n    D -. \"NS reply\" .-\u003e V\n```\n\n```mermaid\nflowchart LR\n    subgraph VICTIM\n        V[\"💻 polling\"]\n    end\n    subgraph ATTACKER\n        A[\"🖥 HTTP :80\"]\n    end\n\n    V -- \"① GET /token\\npoll for cmd\" --\u003e A\n    A -. \"② 200 encoded cmd\" .-\u003e V\n    V -- \"③ POST /token\\nencoded output\" --\u003e A\n```\n\n```mermaid\nflowchart LR\n    subgraph VICTIM\n        V[\"💻 :random\"]\n    end\n    subgraph ATTACKER\n        A[\"🖥 :443 LISTEN\"]\n    end\n\n    V -- \"① TLS handshake\" --\u003e A\n    A -- \"② 🔒 encrypted cmd\" --\u003e V\n    V -- \"③ 🔒 encrypted output\" --\u003e A\n\n    style A fill:#1a1200,stroke:#cc9900\n    style V fill:#1a0000,stroke:#ff4444\n```\n\n---\n\n## Shell Obfuscation\n\nEach shell that contains an interpreter supports **dynamic obfuscation** — click `▶ obf` to cycle modes without leaving the page.\n\n```mermaid\nstateDiagram-v2\n    [*] --\u003e plain\n    plain --\u003e base64 : click obf\n    base64 --\u003e var_split : click obf\n    var_split --\u003e hex_printf : click obf\n    hex_printf --\u003e plain : click obf\n\n    state \"bash base64\" as base64\n    note right of base64\n        bash -c \"$(echo '...'|base64 -d)\"\n    end note\n\n    state \"$var split\" as var_split\n    note right of var_split\n        b='ba';s='sh'; eval $b$s${IFS}-i...\n    end note\n\n    state \"hex printf\" as hex_printf\n    note right of hex_printf\n        eval \"$(printf '\\x62\\x61\\x73\\x68...')\"\n    end note\n```\n\n**Obfuscation modes per interpreter:**\n\n| Interpreter | Modes |\n|------------|-------|\n| Bash / Zsh / Sh | `base64` · `$var split` · `hex printf` |\n| PowerShell | `-EncodedCommand` (UTF-16LE) · `[char[]]` IEX |\n| Python | `exec(base64.b64decode(...))` |\n| Perl | `eval(pack('H*', hex))` |\n| PHP | `eval(base64_decode(...))` |\n| Ruby | `eval(Base64.decode64(...))` |\n\n---\n\n## Encrypted Shells\n\nShells with encrypted transport are highlighted in **gold** and carry a 🔒 badge.\n\n```mermaid\nflowchart TD\n    subgraph Encrypted[\"🔒 Encrypted Transport\"]\n        direction LR\n        E1[\"OpenSSL s_client\"]\n        E2[\"PowerShell TLS #4\"]\n        E3[\"Ncat --ssl\"]\n        E4[\"HoaxShell HTTPS\"]\n        E5[\"SSL-AES C++ Shell\"]\n        E6[\"Chashell DNS (XSalsa20)\"]\n    end\n```\n\nUse the **🔒 encrypted** filter chip to show only these shells.\n\n---\n\n## Living off the Land\n\nTechniques organised by OS, each with its own filter view.\n\n```mermaid\nmindmap\n  root((LotL))\n    Windows\n      Download \u0026 Execute\n        certutil\n        bitsadmin\n        curl Win10+\n        PowerShell cradle\n      Code Execution\n        mshta HTA\n        regsvr32 Squiblydoo\n        rundll32 JS\n        MSBuild C#\n        InstallUtil\n        wmic\n      Persistence\n        Registry Run key\n        Scheduled Task\n        Startup folder\n    Linux\n      Download \u0026 Execute\n        curl pipe bash\n        wget pipe bash\n        python3 fetch\n      File Transfer\n        nc / socat\n        dd raw\n        base64 paste\n      Tunneling\n        SSH reverse tunnel\n        SSH SOCKS5\n        Chisel\n      Persistence\n        crontab\n        systemd user service\n        LD_PRELOAD\n    macOS\n      Download \u0026 Execute\n        curl pipe bash\n        osascript\n      Persistence\n        LaunchAgent plist\n        crontab\n```\n\n---\n\n## Tools \u0026 Listeners\n\n| Tool | Type | Platform |\n|------|------|----------|\n| [pwncat-cs](https://github.com/calebstewart/pwncat) | Post-exploitation platform | Linux |\n| [pwncat (cytopia)](https://github.com/cytopia/pwncat) | Netcat on steroids | Linux / Mac / Win |\n| [Chashell](https://github.com/kost/chashell) | DNS reverse shell | All |\n| [HellShell](https://github.com/NUL0x4C/HellShell) | Shellcode obfuscator | Windows |\n| [SSL-AES Reverse Shell](https://github.com/V-i-x-x/SSL-AES-Reverse-Shell) | TLS C++ shell | Windows |\n| [FuegoShell](https://github.com/v1k1ngfr/fuegoshell) | SMB named-pipe shell | Windows |\n| [CHAOS RAT](https://github.com/tiagorlampert/CHAOS) | Go RAT with web UI | Linux / Win |\n| [tmate](https://github.com/tmate-io/tmate) | Terminal sharing via SSH | Linux / Mac |\n\n---\n\n## Usage\n\n```bash\n# Option 1 — open directly in browser (no server needed)\nopen index.html   # macOS\nstart index.html  # Windows\nxdg-open index.html  # Linux\n\n# Option 2 — serve locally\npython3 -m http.server 8080\n# → http://localhost:8080\n```\n\n1. Set **LHOST / IP**, **PORT**, and preferred **shell binary**\n2. Pick a **listener** from the dropdown — the attacker-side command auto-updates\n3. Use the **filter chips** to narrow by OS, encryption, or obfuscation support\n4. Click a shell to expand — diagram animates, copy button is ready\n5. Optionally click **▶ obf** to cycle through obfuscation modes before copying\n\n---\n\n## Listener Dropdown\n\n```mermaid\nflowchart LR\n    L[\"Listener Dropdown\"] --\u003e NC[\"nc -lvnp PORT\"]\n    L --\u003e NCAT[\"ncat -lvnp PORT\"]\n    L --\u003e SOCAT[\"socat file:tty,raw TCP-LISTEN:PORT\"]\n    L --\u003e RLWRAP[\"rlwrap nc -lvnp PORT  (TTY)\"]\n    L --\u003e MSF[\"msf multi/handler\"]\n    L --\u003e PCS[\"pwncat-cs -lp PORT\"]\n    L --\u003e PCY[\"pwncat -l -p PORT\"]\n```\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fraccshells","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbenjitrapp%2Fraccshells","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fraccshells/lists"}