Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Romaryo
Collaborator

Python reverse shell communicating over ports 80 or 443

Hello colleagues,

I have a question: Do you have any ideas on how to detect and block a Python reverse shell communicating over ports 80 or 443?

Thank you in advance!

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Outbound? Instead of allowing 80/443 via http/https service, use "Web Browsing" to ensure it's proper HTTP traffic (which Reverse Shell typically is not).
However, that assumes we're talking about a Check Point gateway and, based on where this is posted, it's not clear what product(s) are relevant to this query.

0 Kudos
Romaryo
Collaborator

Yes, this involves a Check Point firewall gateway. An attacker initiates a connection from an internal host, for example by using a PowerShell script or Python code. This establishes a reverse shell channel, enabling bidirectional communication between the compromised system and the attacker.

 

 

0 Kudos
Romaryo
Collaborator

Offtopic: Sorry, wie kann ich den Beitrag in die richtige Kategorie verschieben?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events