What is a shell?
TL;DR
A “shell” is just command-line access to a machine. In testing you’ll hear bind and reverse shells: the difference is simply who connects to whom.
What it is
Getting a shell on a target means getting a command prompt on it — the ability to run commands. It’s the moment a test goes from “I found a way in” to “I’m in”.
Bind vs reverse
- Bind shell: the target opens a port and waits; you connect to it. Simple, but firewalls usually block inbound connections, so it often won’t work.
- Reverse shell: the target connects back out to you. Because outbound traffic is usually allowed, this is what actually works most of the time.
You’ll also hear about upgrading a “dumb” non-interactive shell into a proper interactive one so things like tab-completion and sudo behave.
Why defenders care
Reverse shells mean unexpected outbound connections from a server to an odd address — which is exactly the kind of thing egress filtering and network monitoring are meant to catch.