<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.everybodywiki.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Drive</id>
	<title>EverybodyWiki Bios &amp; Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://en.everybodywiki.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Drive"/>
	<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/Special:Contributions/Drive"/>
	<updated>2026-09-08T11:23:58Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.44.6</generator>
	<entry>
		<id>https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=320573</id>
		<title>Web shell</title>
		<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=320573"/>
		<updated>2019-02-18T14:56:14Z</updated>

		<summary type="html">&lt;p&gt;Drive: spell fixed&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A fuckdoor or vagina is a hole in the body of a women used to enable man o have sex with her . Vaginas are able to infect penises which were not covered using condoms during sex, servers STD such as AIDS or Gonorrhea .&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA15-314A|title=Web Shells – Threat Awareness and Guidance|author=US Department of Homeland Security|date=|website=www.us-cert.gov|accessdate=20 December 2018}} {{PD-notice}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;&amp;gt;{{cite web|url=https://malware.expert/general/what-is-a-web-shell/|title=What is a Web shell?|last=admin|date=3 August 2017|website=malware.expert|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;br&amp;gt; The &lt;br /&gt;
&lt;br /&gt;
Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
mong others.&lt;br /&gt;
&lt;br /&gt;
Webshells are known not to need additional programs to run on victims system since communications happens simply over HTTP on browsers. Uploads of webshells are usually accomplished through document/file upload pages and then a Local File Include (LFI) weakness is used to include webshell in one of the pages of the application. Other forms through which webshells are installed include Cross-site scripting (XSS) and Exposed Admin Interface.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A web shell can be written in any [[programming language]] that the target web server supports. Web shells are most commonly written in [[PHP]], [[Active Server Pages]], or [[ASP.NET]], but [[Perl]], [[Ruby (programming language)|Ruby]], [[Python (programming language)|Python]], and [[Unix shell]] scripts are also used.&amp;lt;ref name=&amp;quot;techtarget.com&amp;quot;&amp;gt;{{cite web|url=https://searchsecurity.techtarget.com/answer/How-can-web-shells-be-used-to-exploit-security-tools-and-servers|title=How can web shells be used to exploit security tools and servers?|website=SearchSecurity}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Using [[Network_monitoring#Notable_network_monitoring_tools|network monitoring tools]] such as [[Wireshark]], an attacker can identify vulnerabilities that can be exploited and result in the installation of a web shell, these vulnerabilities can exist in [[content management system]] (CMS) or [[web server]] software.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
An attacker can use a web shell to issue commands, increase privileges on the web server and include the ability to upload, delete, download and execute files as well as the ability to run shell commands, further executable, or scripts.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Usage==&lt;br /&gt;
Web shells are used in attacks mostly because they are multi-purpose and are difficult to detect.&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA18-074A|title=Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors - US-CERT|author=|date=|website=www.us-cert.gov|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells are commonly used for:&lt;br /&gt;
&lt;br /&gt;
*[[Data theft]]&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&lt;br /&gt;
*Infecting website visitors ([[Watering hole attack|watering hole attacks]])&amp;lt;ref&amp;gt;{{cite web|url=https://fixmywp.com/security/what-are-web-shell-backdoors.php|title=The Definitive Guide about Backdoor Attacks - What are WebShell BackDoors|first1=Makis MourelatosWordPress Security Engineer at FixMyWPWC Athens 2016|last1=co-organizer|first2=W. P.|last2=Support|first3=Security|last3=Aficionado|first4=Wannabe|last4=Kitesurfer|date=16 October 2017|website=fixmywp.com|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*[[Website defacement]] by modifying files with a malicious intent&lt;br /&gt;
*Launch distributed denial of service ([[Denial of service attack#Distributed attack|DDoS]]) attacks&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as a relay point to issue commands to hosts inside the network without direct Internet access&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as command-and-control infrastructure, potentially in the form of a bot in a [[botnet]] or in support of compromises to additional external networks. This could occur if the adversary intends to maintain long-term persistence&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Delivery==&lt;br /&gt;
&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot;&amp;gt;{{cite web|url=http://social.techcrunch.com/2018/12/10/equifax-breach-preventable-house-oversight-report/|title=Equifax breach was &#039;entirely preventable&#039; had it used basic security measures, says House report|publisher=|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*F Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.  &#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;  ions);&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot; /&amp;gt;&lt;br /&gt;
*&lt;br /&gt;
*&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Examples of web shells==&lt;br /&gt;
[[File:B374k_shell_running_on_windows_7_ultimate_edition_server.jpg|thumb|250x200px|A b374k shell running on a Windows 7 Ultimate Edition server]]&lt;br /&gt;
Attackers mostly use web shells such as &amp;quot;China Chopper&amp;quot;, &amp;quot;WSO&amp;quot;, &amp;quot;C99&amp;quot;, and &amp;quot;b374k&amp;quot;.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits. &#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;  .&amp;lt;ref&amp;gt;{{cite web|url=https://www.cyber.nj.gov/threat-profiles/trojan-variants/china-chopper|title=China Chopper|website=NJCCIC|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.andreafortuna.org/cybersecurity/what-is-the-china-chopper-webshell-and-how-to-find-it-on-a-compromized-system/|title=What is the China Chopper Webshell, and how to find it on a compromised system?|date=28 March 2018|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|website=FireEye|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;php&amp;quot;&amp;gt;i am not a bitch but just you fuck off you curry nigger get lost from usa we dont wanna see your cult face you got id txzrstcmn stst that ks babe id like to fuck katrina kaif &amp;lt;/source&amp;gt;&lt;br /&gt;
If the attacker gets this line of code into a malicious file with a &amp;lt;code&amp;gt;.php&amp;lt;/code&amp;gt; extension on the [[web server]] that is running [[PHP]], the attacker can issue commands, for example reading the &amp;lt;code&amp;gt;[[Passwd#Password file|/etc/passwd]]&amp;lt;/code&amp;gt; file, through a web browser using the following [[URL|Uniform Resource Locator]] if the web shell was located at &amp;lt;code&amp;gt;/uploads/webshell.php&amp;lt;/code&amp;gt;:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;https://example.com/uploads/webshell.php?x=cat%20%2Fetc%2Fpasswd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above request will take the value of the &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; URL parameter, decode the URL it and send the following [[Bash (Unix shell)|Bash]] command:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/passwd&amp;lt;/source&amp;gt;&lt;br /&gt;
If the permissions of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file allow vave many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various &lt;br /&gt;
&lt;br /&gt;
This attack could have been prevented if the file permissions did not allow viewing the file or if the [[Shell (computing)|shell]] functions of [[PHP]] were disabled so that arbitrary shell commands cannot be executed from PHP.&lt;br /&gt;
&lt;br /&gt;
Other malicious actions are able to be executed by attackers with the web shell, such as replacing the contents of a file on the [[web server]]. For example, the [[Bash (Unix shell)|Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;echo Hijacked page contents &amp;gt; index.php&amp;lt;/source&amp;gt; could be used to replace the contents of the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the text &amp;quot;Hijacked page contents&amp;quot;, which is one way a web page could be defaced, or create the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the contents if the file does not exist. Attackers can also use the [[Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;rm&amp;lt;/source&amp;gt; to delete files on the web server.&lt;br /&gt;
&lt;br /&gt;
==Prevention and mitigation==&lt;br /&gt;
Shells&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*fccgchnhs&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*e jchmrs&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*kilchcjhm ws&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Use a [[reverse proxy]] service to restrict the administrative URL&#039;s to known legitimate ones &amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;[[Zero-day (computing)|tacks]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;[[Firewall (computing)|ewall]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Disable directory browsing&lt;br /&gt;
*Not using default login credentials&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Detection==&lt;br /&gt;
Thells.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|author=|date=|website=FireEye|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
The following may be indicators that a web server has been infected by a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abnormaker);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;cious kn server logs&lt;br /&gt;
&lt;br /&gt;
For example: A file type generating anomalous network traffic (e.g., a [[JPEG|JPG]] file making requests with POST parameters);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;https://ws680.nist.gov/publication/get_pdf.cfm?pub_id=901146&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.networkworld.com/article/3085141/network-security/five-signs-an-attacker-is-already-in-your-network.html|title=Five signs an attacker is already in your network|first=Kasey Cross, Senior Product Manager|last=LightCyber|date=16 June 2016|website=Network World|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web | url=https://insights.sei.cmu.edu/sei_blog/2016/09/traffic-analysis-for-network-security-two-approaches-for-going-beyond-network-flow-data.html | title=Traffic Analysis for Network Security: Two Approaches for Going Beyond Network Flow Data}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
sa.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Attackers can also hide web shell logins in fake [[HTTP error|error pages]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.bleepingcomputer.com/news/security/hackers-hiding-web-shell-logins-in-fake-http-error-pages/|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=BleepingComputer|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;https://threatravens.com/hackers-hiding-web-shell-logins-in-fake-http-error-pages/&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://cyware.com/news/hackers-hiding-web-shell-logins-in-fake-http-error-pages-f9f1b47e|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=cyware.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;ne of the search engine bots is usually required. Once the shell is detected, it can be deleted easily.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;efore have very few variants of user-agent strings.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
&lt;br /&gt;
*[[Backdoor (computing)]]&lt;br /&gt;
*[[Cyberwarfare]]&lt;br /&gt;
*[[Internet security]]&lt;br /&gt;
*[[Network security]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
{{Malware}}&lt;br /&gt;
{{Authority control}}&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
[[Category:Web security exploits]]&lt;br /&gt;
[[Category:Hacking (computer security)]]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
{{Source Wikipedia}}&lt;/div&gt;</summary>
		<author><name>Drive</name></author>
	</entry>
	<entry>
		<id>https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=320572</id>
		<title>Web shell</title>
		<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=320572"/>
		<updated>2019-02-18T14:52:50Z</updated>

		<summary type="html">&lt;p&gt;Drive: added some content from wikipedia&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A web shell or backdoor shell is a script written in the supported language of a target web server to be uploaded to enable remote access and administration of the machine. Shells are able to infect servers that may not necessary be internet-facing, servers for hosting of internal resources are also subject to web shell attacks where script owners try to access information saved on this systems.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA15-314A|title=Web Shells – Threat Awareness and Guidance|author=US Department of Homeland Security|date=|website=www.us-cert.gov|accessdate=20 December 2018}} {{PD-notice}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;&amp;gt;{{cite web|url=https://malware.expert/general/what-is-a-web-shell/|title=What is a Web shell?|last=admin|date=3 August 2017|website=malware.expert|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;br&amp;gt; The &lt;br /&gt;
&lt;br /&gt;
Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
mong others.&lt;br /&gt;
&lt;br /&gt;
Webshells are known not to need additional programs to run on victims system since communications happens simply over HTTP on browsers. Uploads of webshells are usually accomplished through document/file upload pages and then a Local File Include (LFI) weakness is used to include webshell in one of the pages of the application. Other forms through which webshells are installed include Cross-site scripting (XSS) and Exposed Admin Interface.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A web shell can be written in any [[programming language]] that the target web server supports. Web shells are most commonly written in [[PHP]], [[Active Server Pages]], or [[ASP.NET]], but [[Perl]], [[Ruby (programming language)|Ruby]], [[Python (programming language)|Python]], and [[Unix shell]] scripts are also used.&amp;lt;ref name=&amp;quot;techtarget.com&amp;quot;&amp;gt;{{cite web|url=https://searchsecurity.techtarget.com/answer/How-can-web-shells-be-used-to-exploit-security-tools-and-servers|title=How can web shells be used to exploit security tools and servers?|website=SearchSecurity}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Using [[Network_monitoring#Notable_network_monitoring_tools|network monitoring tools]] such as [[Wireshark]], an attacker can identify vulnerabilities that can be exploited and result in the installation of a web shell, these vulnerabilities can exist in [[content management system]] (CMS) or [[web server]] software.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
An attacker can use a web shell to issue commands, increase privileges on the web server and include the ability to upload, delete, download and execute files as well as the ability to run shell commands, further executable, or scripts.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Usage==&lt;br /&gt;
Web shells are used in attacks mostly because they are multi-purpose and are difficult to detect.&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA18-074A|title=Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors - US-CERT|author=|date=|website=www.us-cert.gov|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells are commonly used for:&lt;br /&gt;
&lt;br /&gt;
*[[Data theft]]&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&lt;br /&gt;
*Infecting website visitors ([[Watering hole attack|watering hole attacks]])&amp;lt;ref&amp;gt;{{cite web|url=https://fixmywp.com/security/what-are-web-shell-backdoors.php|title=The Definitive Guide about Backdoor Attacks - What are WebShell BackDoors|first1=Makis MourelatosWordPress Security Engineer at FixMyWPWC Athens 2016|last1=co-organizer|first2=W. P.|last2=Support|first3=Security|last3=Aficionado|first4=Wannabe|last4=Kitesurfer|date=16 October 2017|website=fixmywp.com|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*[[Website defacement]] by modifying files with a malicious intent&lt;br /&gt;
*Launch distributed denial of service ([[Denial of service attack#Distributed attack|DDoS]]) attacks&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as a relay point to issue commands to hosts inside the network without direct Internet access&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as command-and-control infrastructure, potentially in the form of a bot in a [[botnet]] or in support of compromises to additional external networks. This could occur if the adversary intends to maintain long-term persistence&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Delivery==&lt;br /&gt;
&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot;&amp;gt;{{cite web|url=http://social.techcrunch.com/2018/12/10/equifax-breach-preventable-house-oversight-report/|title=Equifax breach was &#039;entirely preventable&#039; had it used basic security measures, says House report|publisher=|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*F Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.  &#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;  ions);&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot; /&amp;gt;&lt;br /&gt;
*&lt;br /&gt;
*&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Examples of web shells==&lt;br /&gt;
[[File:B374k_shell_running_on_windows_7_ultimate_edition_server.jpg|thumb|250x200px|A b374k shell running on a Windows 7 Ultimate Edition server]]&lt;br /&gt;
Attackers mostly use web shells such as &amp;quot;China Chopper&amp;quot;, &amp;quot;WSO&amp;quot;, &amp;quot;C99&amp;quot;, and &amp;quot;b374k&amp;quot;.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits. &#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;  .&amp;lt;ref&amp;gt;{{cite web|url=https://www.cyber.nj.gov/threat-profiles/trojan-variants/china-chopper|title=China Chopper|website=NJCCIC|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.andreafortuna.org/cybersecurity/what-is-the-china-chopper-webshell-and-how-to-find-it-on-a-compromized-system/|title=What is the China Chopper Webshell, and how to find it on a compromised system?|date=28 March 2018|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|website=FireEye|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;php&amp;quot;&amp;gt;i am not a bitch but just you fuck off you curry nigger get lost from usa we dont wanna see your cult face you got id txzrstcmn stst that ks babe id like to fuck katrina kaif &amp;lt;/source&amp;gt;&lt;br /&gt;
If the attacker gets this line of code into a malicious file with a &amp;lt;code&amp;gt;.php&amp;lt;/code&amp;gt; extension on the [[web server]] that is running [[PHP]], the attacker can issue commands, for example reading the &amp;lt;code&amp;gt;[[Passwd#Password file|/etc/passwd]]&amp;lt;/code&amp;gt; file, through a web browser using the following [[URL|Uniform Resource Locator]] if the web shell was located at &amp;lt;code&amp;gt;/uploads/webshell.php&amp;lt;/code&amp;gt;:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;https://example.com/uploads/webshell.php?x=cat%20%2Fetc%2Fpasswd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above request will take the value of the &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; URL parameter, decode the URL it and send the following [[Bash (Unix shell)|Bash]] command:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/passwd&amp;lt;/source&amp;gt;&lt;br /&gt;
If the permissions of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file allow vave many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various &lt;br /&gt;
&lt;br /&gt;
This attack could have been prevented if the file permissions did not allow viewing the file or if the [[Shell (computing)|shell]] functions of [[PHP]] were disabled so that arbitrary shell commands cannot be executed from PHP.&lt;br /&gt;
&lt;br /&gt;
Other malicious actions are able to be executed by attackers with the web shell, such as replacing the contents of a file on the [[web server]]. For example, the [[Bash (Unix shell)|Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;echo Hijacked page contents &amp;gt; index.php&amp;lt;/source&amp;gt; could be used to replace the contents of the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the text &amp;quot;Hijacked page contents&amp;quot;, which is one way a web page could be defaced, or create the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the contents if the file does not exist. Attackers can also use the [[Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;rm&amp;lt;/source&amp;gt; to delete files on the web server.&lt;br /&gt;
&lt;br /&gt;
==Prevention and mitigation==&lt;br /&gt;
Shells&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*fccgchnhs&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*e jchmrs&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*kilchcjhm ws&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Use a [[reverse proxy]] service to restrict the administrative URL&#039;s to known legitimate ones &amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;[[Zero-day (computing)|tacks]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;[[Firewall (computing)|ewall]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Disable directory browsing&lt;br /&gt;
*Not using default login credentials&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Detection==&lt;br /&gt;
Thells.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|author=|date=|website=FireEye|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
The following may be indicators that a web server has been infected by a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abnormaker);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;cious kn server logs&lt;br /&gt;
&lt;br /&gt;
For example: A file type generating anomalous network traffic (e.g., a [[JPEG|JPG]] file making requests with POST parameters);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;https://ws680.nist.gov/publication/get_pdf.cfm?pub_id=901146&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.networkworld.com/article/3085141/network-security/five-signs-an-attacker-is-already-in-your-network.html|title=Five signs an attacker is already in your network|first=Kasey Cross, Senior Product Manager|last=LightCyber|date=16 June 2016|website=Network World|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web | url=https://insights.sei.cmu.edu/sei_blog/2016/09/traffic-analysis-for-network-security-two-approaches-for-going-beyond-network-flow-data.html | title=Traffic Analysis for Network Security: Two Approaches for Going Beyond Network Flow Data}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shells have many uses. They can be used to edit the webserver directory index page of site, and then hackers can leave their mark or &amp;quot;deface&amp;quot; for visitors to the site to see when they go to the homepage. Hackers may also use it to bruteforce FTP or cPanel, allowing them more access to the website. Shells can also be used to gain root access to the site. Some hackers may choose to host malware or spyware on the sites they have uploaded their shell to using various exploits.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please note that many shells contain malware and &#039;Mark / deface page&#039; might contain malware to obtain visitor&#039;s password as well.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
sa.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Attackers can also hide web shell logins in fake [[HTTP error|error pages]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.bleepingcomputer.com/news/security/hackers-hiding-web-shell-logins-in-fake-http-error-pages/|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=BleepingComputer|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;https://threatravens.com/hackers-hiding-web-shell-logins-in-fake-http-error-pages/&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://cyware.com/news/hackers-hiding-web-shell-logins-in-fake-http-error-pages-f9f1b47e|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=cyware.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;ne of the search engine bots is usually required. Once the shell is detected, it can be deleted easily.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;efore have very few variants of user-agent strings.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
&lt;br /&gt;
*[[Backdoor (computing)]]&lt;br /&gt;
*[[Cyberwarfare]]&lt;br /&gt;
*[[Internet security]]&lt;br /&gt;
*[[Network security]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
{{Malware}}&lt;br /&gt;
{{Authority control}}&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
[[Category:Web security exploits]]&lt;br /&gt;
[[Category:Hacking (computer security)]]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
{{Source Wikipedia}}&lt;/div&gt;</summary>
		<author><name>Drive</name></author>
	</entry>
	<entry>
		<id>https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=313291</id>
		<title>Web shell</title>
		<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=313291"/>
		<updated>2019-02-11T15:59:36Z</updated>

		<summary type="html">&lt;p&gt;Drive: Added clearer language&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A web shell or backdoor shell is a script written in the supported language of a target web server to be uploaded to enable remote access and administration of the machine. Shells are able to infect servers that may not necessary be internet-facing, servers for hosting of internal resources are also subject to web shell attacks where script owners try to access information saved on this systems.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA15-314A|title=Web Shells – Threat Awareness and Guidance|author=US Department of Homeland Security|date=|website=www.us-cert.gov|accessdate=20 December 2018}} {{PD-notice}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;&amp;gt;{{cite web|url=https://malware.expert/general/what-is-a-web-shell/|title=What is a Web shell?|last=admin|date=3 August 2017|website=malware.expert|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;br&amp;gt; The shell gives the creator the ability to create, edit, delete or download any file of choice, top of the list for infiltrators is using a web shell to gain root access to server. It is also important to note that web and system administrators also use shells to perform routine tasks like creation of users, reading of logs among others.&lt;br /&gt;
&lt;br /&gt;
Webshells are known not to need additional programs to run on victims system since communications happens simply over HTTP on browsers. Uploads of webshells are usually accomplished through document/file upload pages and then a Local File Include (LFI) weakness is used to include webshell in one of the pages of the application. Other forms through which webshells are installed include Cross-site scripting (XSS) and Exposed Admin Interface.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A web shell can be written in any [[programming language]] that the target web server supports. Web shells are most commonly written in [[PHP]], [[Active Server Pages]], or [[ASP.NET]], but [[Perl]], [[Ruby (programming language)|Ruby]], [[Python (programming language)|Python]], and [[Unix shell]] scripts are also used.&amp;lt;ref name=&amp;quot;techtarget.com&amp;quot;&amp;gt;{{cite web|url=https://searchsecurity.techtarget.com/answer/How-can-web-shells-be-used-to-exploit-security-tools-and-servers|title=How can web shells be used to exploit security tools and servers?|website=SearchSecurity}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Using [[Network_monitoring#Notable_network_monitoring_tools|network monitoring tools]] such as [[Wireshark]], an attacker can identify vulnerabilities that can be exploited and result in the installation of a web shell, these vulnerabilities can exist in [[content management system]] (CMS) or [[web server]] software.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
An attacker can use a web shell to issue commands, increase privileges on the web server and include the ability to upload, delete, download and execute files as well as the ability to run shell commands, further executable, or scripts.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Usage==&lt;br /&gt;
Web shells are used in attacks mostly because they are multi-purpose and are difficult to detect.&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA18-074A|title=Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors - US-CERT|author=|date=|website=www.us-cert.gov|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells are commonly used for:&lt;br /&gt;
&lt;br /&gt;
*[[Data theft]]&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&lt;br /&gt;
*Infecting website visitors ([[Watering hole attack|watering hole attacks]])&amp;lt;ref&amp;gt;{{cite web|url=https://fixmywp.com/security/what-are-web-shell-backdoors.php|title=The Definitive Guide about Backdoor Attacks - What are WebShell BackDoors|first1=Makis MourelatosWordPress Security Engineer at FixMyWPWC Athens 2016|last1=co-organizer|first2=W. P.|last2=Support|first3=Security|last3=Aficionado|first4=Wannabe|last4=Kitesurfer|date=16 October 2017|website=fixmywp.com|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*[[Website defacement]] by modifying files with a malicious intent&lt;br /&gt;
*Launch distributed denial of service ([[Denial of service attack#Distributed attack|DDoS]]) attacks&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as a relay point to issue commands to hosts inside the network without direct Internet access&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*To use as command-and-control infrastructure, potentially in the form of a bot in a [[botnet]] or in support of compromises to additional external networks. This could occur if the adversary intends to maintain long-term persistence&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Delivery==&lt;br /&gt;
Web shells can be delivered through a number of web application vulnerabilities or server configuration weaknesses including:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[[Cross-site scripting]];&lt;br /&gt;
*[[SQL injection]];&lt;br /&gt;
*Vulnerabilities in applications and services (e.g., server software such as [[Nginx|NGINX]] or [[content management system]] applications);&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot;&amp;gt;{{cite web|url=http://social.techcrunch.com/2018/12/10/equifax-breach-preventable-house-oversight-report/|title=Equifax breach was &#039;entirely preventable&#039; had it used basic security measures, says House report|publisher=|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*File processing vulnerabilities (e.g., upload filtering or assigned permissions);&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot; /&amp;gt;&lt;br /&gt;
*[[File inclusion vulnerability|Remote file inclusion]] (RFI) and [[File_inclusion_vulnerability#Local_File_Inclusion|local file inclusion]] (LFI) vulnerabilities;&lt;br /&gt;
*Exposed administration interfaces&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Examples of web shells==&lt;br /&gt;
[[File:B374k_shell_running_on_windows_7_ultimate_edition_server.jpg|thumb|250x200px|A b374k shell running on a Windows 7 Ultimate Edition server]]&lt;br /&gt;
Attackers mostly use web shells such as &amp;quot;China Chopper&amp;quot;, &amp;quot;WSO&amp;quot;, &amp;quot;C99&amp;quot;, and &amp;quot;b374k&amp;quot;.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;China Chopper&#039;&#039;&#039; – A web shell with 4 [[Kilobyte|kilobytes]] in size, which was first discovered in 2012. This web shell is widely used by Chinese and other malicious actors, including APT groups, to remotely access compromised [[web server|web servers]]. This web shell consists of two parts, the client interface (an [[Executable|executable file]]) and the [[Computer file|file]] on the compromised web server. Has several commands and control features including a password [[Brute-force attack|brute force]] capability.&amp;lt;ref&amp;gt;{{cite web|url=https://www.cyber.nj.gov/threat-profiles/trojan-variants/china-chopper|title=China Chopper|website=NJCCIC|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.andreafortuna.org/cybersecurity/what-is-the-china-chopper-webshell-and-how-to-find-it-on-a-compromized-system/|title=What is the China Chopper Webshell, and how to find it on a compromised system?|date=28 March 2018|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|website=FireEye|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;b374k&#039;&#039;&#039; – A [[PHP]] based web shell with common functionality such as viewing processes and executing commands.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://code.google.com/archive/p/b374k-shell/|title=Google Code Archive - Long-term storage for Google Code Project Hosting.|website=code.google.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/the-webshell-game-continues/|title=The Webshell Game Continues|date=8 July 2016|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;C99&#039;&#039;&#039; – A version of the WSO shell which has the ability to display the server&#039;s security measures and contains a self-delete function.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;WSO (web shell by orb)&#039;&#039;&#039; – Has the ability to pretend as an [[HTML]] error page containing a hidden login form.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.wordfence.com/blog/2017/06/wso-shell/|title=WSO Shell: The Hack Is Coming From Inside The House!|date=22 June 2017|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://news.netcraft.com/archives/2017/05/18/web-shells-the-criminals-control-panel.html|title=Web Shells: The Criminal&#039;s Control Panel - Netcraft|website=news.netcraft.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells can be as short as just one line of code, for example this [[PHP]] script which is 15 [[byte|bytes]] long:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;php&amp;quot;&amp;gt;&amp;lt;?=`$_GET[x]`?&amp;gt;&amp;lt;/source&amp;gt;&lt;br /&gt;
If the attacker gets this line of code into a malicious file with a &amp;lt;code&amp;gt;.php&amp;lt;/code&amp;gt; extension on the [[web server]] that is running [[PHP]], the attacker can issue commands, for example reading the &amp;lt;code&amp;gt;[[Passwd#Password file|/etc/passwd]]&amp;lt;/code&amp;gt; file, through a web browser using the following [[URL|Uniform Resource Locator]] if the web shell was located at &amp;lt;code&amp;gt;/uploads/webshell.php&amp;lt;/code&amp;gt;:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;https://example.com/uploads/webshell.php?x=cat%20%2Fetc%2Fpasswd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above request will take the value of the &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; URL parameter, decode the URL it and send the following [[Bash (Unix shell)|Bash]] command:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/passwd&amp;lt;/source&amp;gt;&lt;br /&gt;
If the permissions of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file allow viewing the file, the web server will send the contents of &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; to the [[Web browser|browser]] and the browser will then display the contents of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file or any other file the attacker wishes to view.&lt;br /&gt;
&lt;br /&gt;
This attack could have been prevented if the file permissions did not allow viewing the file or if the [[Shell (computing)|shell]] functions of [[PHP]] were disabled so that arbitrary shell commands cannot be executed from PHP.&lt;br /&gt;
&lt;br /&gt;
Other malicious actions are able to be executed by attackers with the web shell, such as replacing the contents of a file on the [[web server]]. For example, the [[Bash (Unix shell)|Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;echo Hijacked page contents &amp;gt; index.php&amp;lt;/source&amp;gt; could be used to replace the contents of the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the text &amp;quot;Hijacked page contents&amp;quot;, which is one way a web page could be defaced, or create the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the contents if the file does not exist. Attackers can also use the [[Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline=&amp;quot;&amp;quot;&amp;gt;rm&amp;lt;/source&amp;gt; to delete files on the web server.&lt;br /&gt;
&lt;br /&gt;
==Prevention and mitigation==&lt;br /&gt;
Installation of a web shell is commonly accomplished through web application vulnerabilities or configuration weaknesses. Therefore, removal of these vulnerabilities are important to avoid potential compromisation of a web server&amp;lt;br&amp;gt;&lt;br /&gt;
The following are security measures for preventing the installation of a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Regularly update the applications and the host servers&#039;s [[operating system]] to ensure protection against known [[Software bug|bugs]]&lt;br /&gt;
*Deploy [[DMZ (computing)|demilitarized zone]] (DMZ) between the web facing servers and the internal networks&lt;br /&gt;
*Secure configuration of the web server&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Unnecessary services and [[Port (computer networking)|ports]] should be closed/blocked&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Employ user input validation to restrict local and [[File inclusion vulnerability|remote file inclusion vulnerabilities]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Use a [[reverse proxy]] service to restrict the administrative URL&#039;s to known legitimate ones &amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Frequent vulnerability scan to detect areas of risk and conduct regular [[Computer virus|virus]] signature checks (this method does not protect against [[Zero-day (computing)|zero day attacks]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;)&lt;br /&gt;
*Deploy a web application [[Firewall (computing)|firewall]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
*Disable directory browsing&lt;br /&gt;
*Not using default login credentials&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Detection==&lt;br /&gt;
The ease of modification of a web shell makes it considerably hard to detect by system administrators, because it is equally not easy for programs developed with the aim of detecting [[Computer virus|viruses]]. For example, [[Antivirus software|anti-virus]] products sometimes produce poor results in detecting web shells.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|author=|date=|website=FireEye|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
The following may be indicators that a web server has been infected by a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abnormal high site usage (due to potential uploading and downloading activity by the attacker);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;&lt;br /&gt;
Files with an unusual timestamp (e.g., more recent than the last time the files were modified.);&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot; /&amp;gt;&lt;br /&gt;
Suspicious files in Internet-accessible locations (web root);&lt;br /&gt;
Files containing references to suspicious keywords such as cmd.exe or eval;&lt;br /&gt;
Unexpected connections in server logs&lt;br /&gt;
&lt;br /&gt;
For example: A file type generating anomalous network traffic (e.g., a [[JPEG|JPG]] file making requests with POST parameters);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;https://ws680.nist.gov/publication/get_pdf.cfm?pub_id=901146&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.networkworld.com/article/3085141/network-security/five-signs-an-attacker-is-already-in-your-network.html|title=Five signs an attacker is already in your network|first=Kasey Cross, Senior Product Manager|last=LightCyber|date=16 June 2016|website=Network World|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web | url=https://insights.sei.cmu.edu/sei_blog/2016/09/traffic-analysis-for-network-security-two-approaches-for-going-beyond-network-flow-data.html | title=Traffic Analysis for Network Security: Two Approaches for Going Beyond Network Flow Data}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
Suspicious logins originating from internal subnets to [[DMZ (computing)|DMZ]] servers and vice versa.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Attackers can also hide web shell logins in fake [[HTTP error|error pages]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.bleepingcomputer.com/news/security/hackers-hiding-web-shell-logins-in-fake-http-error-pages/|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=BleepingComputer|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;https://threatravens.com/hackers-hiding-web-shell-logins-in-fake-http-error-pages/&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://cyware.com/news/hackers-hiding-web-shell-logins-in-fake-http-error-pages-f9f1b47e|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=cyware.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Often, web shells will be used to spread [[malware]] onto a server and the [[search engines]] are able to see it. Attackers are known to alter the [[.htaccess]] files on the server to redirect [[Web search engine|search engine]] requests to the [[Web page|webpage]] with [[malware]] or [[Spamming|spam]]. Many web shells check the [[User agent|user-agent]] and the content presented to the [[search engine spider]] is different from that presented to the user&#039;s browser. To find a shell a [[User agent|user-agent]] change to one of the search engine bots is usually required. Once the shell is detected, it can be deleted easily.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performing frequency analysis on the web server&#039;s access logs could indicate the location of a web shell. Most legitimate visits will have different [[User agent|user-agent]]s and [[HTTP referer|referrers (referers)]], whereas a web shell is only visited by the attacker, therefore have very few variants of user-agent strings.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
&lt;br /&gt;
*[[Backdoor (computing)]]&lt;br /&gt;
*[[Cyberwarfare]]&lt;br /&gt;
*[[Internet security]]&lt;br /&gt;
*[[Network security]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
{{Malware}}&lt;br /&gt;
{{Authority control}}&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
[[Category:Web security exploits]]&lt;br /&gt;
[[Category:Hacking (computer security)]]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
{{Source Wikipedia}}&lt;/div&gt;</summary>
		<author><name>Drive</name></author>
	</entry>
	<entry>
		<id>https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=299575</id>
		<title>Web shell</title>
		<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/index.php?title=Web_shell&amp;diff=299575"/>
		<updated>2019-01-25T07:11:35Z</updated>

		<summary type="html">&lt;p&gt;Drive: rmv - shit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A &#039;&#039;&#039;web shell&#039;&#039;&#039; is a  web-based implementation of the [[Shell (computing)|shell concept]] that can be uploaded to a [[web server]] to enable [[Remote administration|remote administration]] of the web server.&amp;lt;ref name=&amp;quot;techtarget.com&amp;quot;&amp;gt;{{cite web|url=https://searchsecurity.techtarget.com/answer/How-can-web-shells-be-used-to-exploit-security-tools-and-servers|title=How can web shells be used to exploit security tools and servers?|website=SearchSecurity}}&amp;lt;/ref&amp;gt; A web shell is unique in that it enables users to operate a remote computer by way of a [[web browser]] that acts like a [[command-line interface]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;/&amp;gt;&amp;lt;br&amp;gt; A user can sign onto a [[remote computer]] via the [[World Wide Web]] using a [[web browser]] on any type of system, whether it&#039;s a desktop computer or a web-enabled [[mobile phone]], and perform tasks on the remote system. No command-line environment is required on either the host or the client. Web shells are used as backdoors that can run from the [[Web browser|web browser]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;/&amp;gt; Infected web servers can be either connected to the [[Internet]] or internal to the network, where the web shell is used to infect further to internal hosts.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA15-314A|title=Web Shells – Threat Awareness and Guidance|author=US Department of Homeland Security|date=|website=www.us-cert.gov|accessdate=20 December 2018}} {{PD-notice}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;&amp;gt;{{cite web|url=https://malware.expert/general/what-is-a-web-shell/|title=What is a Web shell?|last=admin|date=3 August 2017|website=malware.expert|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A web shell can be written in any [[programming language]] that the target web server supports. Web shells are most commonly written in [[PHP]], [[Active Server Pages]], or [[ASP.NET]], but [[Perl]], [[Ruby (programming language)|Ruby]], [[Python (programming language)|Python]], and [[Unix shell]] scripts are also used.&amp;lt;ref name=&amp;quot;techtarget.com&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Using [[Network_monitoring#Notable_network_monitoring_tools|network monitoring tools]] such as [[Wireshark]], an attacker can identify vulnerabilities that can be exploited and result in the installation of a web shell, these vulnerabilities can exist in [[content management system]] (CMS) or [[web server]] software.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
An attacker can use a web shell to issue commands, increase privileges on the web server and include the ability to upload, delete, download and execute files as well as the ability to run shell commands, further executable, or scripts.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Usage==&lt;br /&gt;
Web shells are used in attacks mostly because they are multi-purpose and are difficult to detect.&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;&amp;gt;{{cite web|url=https://www.us-cert.gov/ncas/alerts/TA18-074A|title=Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors - US-CERT|author=|date=|website=www.us-cert.gov|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells are commonly used for:&lt;br /&gt;
* [[Data theft]]&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;/&amp;gt;&lt;br /&gt;
* Infecting website visitors ([[Watering hole attack|watering hole attacks]])&amp;lt;ref&amp;gt;{{cite web|url=https://fixmywp.com/security/what-are-web-shell-backdoors.php|title=The Definitive Guide about Backdoor Attacks - What are WebShell BackDoors|first1=Makis MourelatosWordPress Security Engineer at FixMyWPWC Athens 2016|last1=co-organizer|first2=W. P.|last2=Support|first3=Security|last3=Aficionado|first4=Wannabe|last4=Kitesurfer|date=16 October 2017|website=fixmywp.com|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* [[Website defacement]] by modifying files with a malicious intent&lt;br /&gt;
* Launch distributed denial of service ([[Denial of service attack#Distributed attack|DDoS]]) attacks&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* To use as a relay point to issue commands to hosts inside the network without direct Internet access&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* To use as command-and-control infrastructure, potentially in the form of a bot in a [[botnet]] or in support of compromises to additional external networks. This could occur if the adversary intends to maintain long-term persistence&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Delivery==&lt;br /&gt;
Web shells can be delivered through a number of web application vulnerabilities or server configuration weaknesses including:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;us-cert.gov1&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[Cross-site scripting]];&lt;br /&gt;
* [[SQL injection]];&lt;br /&gt;
* Vulnerabilities in applications and services (e.g., server software such as [[Nginx|NGINX]] or [[content management system]] applications);&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot;&amp;gt;{{cite web|url=http://social.techcrunch.com/2018/12/10/equifax-breach-preventable-house-oversight-report/|title=Equifax breach was &#039;entirely preventable&#039; had it used basic security measures, says House report|publisher=|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* File processing vulnerabilities (e.g., upload filtering or assigned permissions);&amp;lt;ref name=&amp;quot;techcrunch.com&amp;quot;/&amp;gt;&lt;br /&gt;
* [[File inclusion vulnerability|Remote file inclusion]] (RFI) and [[File_inclusion_vulnerability#Local_File_Inclusion|local file inclusion]] (LFI) vulnerabilities;&lt;br /&gt;
* Exposed administration interfaces&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Examples of web shells==&lt;br /&gt;
[[File:B374k_shell_running_on_windows_7_ultimate_edition_server.jpg|thumb|250x200px|A b374k shell running on a Windows 7 Ultimate Edition server]]&lt;br /&gt;
Attackers mostly use web shells such as &amp;quot;China Chopper&amp;quot;, &amp;quot;WSO&amp;quot;, &amp;quot;C99&amp;quot;, and &amp;quot;b374k&amp;quot;.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;China Chopper&#039;&#039;&#039; – A web shell with 4 [[Kilobyte|kilobytes]] in size, which was first discovered in 2012. This web shell is widely used by Chinese and other malicious actors, including APT groups, to remotely access compromised [[web server|web servers]]. This web shell consists of two parts, the client interface (an [[Executable|executable file]]) and the [[Computer file|file]] on the compromised web server. Has several commands and control features including a password [[Brute-force attack|brute force]] capability.&amp;lt;ref&amp;gt;{{cite web|url=https://www.cyber.nj.gov/threat-profiles/trojan-variants/china-chopper|title=China Chopper|website=NJCCIC|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.andreafortuna.org/cybersecurity/what-is-the-china-chopper-webshell-and-how-to-find-it-on-a-compromized-system/|title=What is the China Chopper Webshell, and how to find it on a compromised system?|date=28 March 2018|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|website=FireEye|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;b374k&#039;&#039;&#039; – A [[PHP]] based web shell with common functionality such as viewing processes and executing commands.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://code.google.com/archive/p/b374k-shell/|title=Google Code Archive - Long-term storage for Google Code Project Hosting.|website=code.google.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/the-webshell-game-continues/|title=The Webshell Game Continues|date=8 July 2016|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;C99&#039;&#039;&#039; – A version of the WSO shell which has the ability to display the server&#039;s security measures and contains a self-delete function.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://securityintelligence.com/got-wordpress-php-c99-webshell-attacks-increasing/|title=Got WordPress? PHP C99 Webshell Attacks Increasing|date=14 April 2016|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;WSO (web shell by orb)&#039;&#039;&#039; – Has the ability to pretend as an [[HTML]] error page containing a hidden login form.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.wordfence.com/blog/2017/06/wso-shell/|title=WSO Shell: The Hack Is Coming From Inside The House!|date=22 June 2017|publisher=|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://news.netcraft.com/archives/2017/05/18/web-shells-the-criminals-control-panel.html|title=Web Shells: The Criminal&#039;s Control Panel - Netcraft|website=news.netcraft.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Web shells can be as short as just one line of code, for example this [[PHP]] script which is 15 [[byte|bytes]] long:&lt;br /&gt;
 &amp;lt;source lang=&amp;quot;php&amp;quot;&amp;gt;&amp;lt;?=`$_GET[x]`?&amp;gt;&amp;lt;/source&amp;gt;&lt;br /&gt;
If the attacker gets this line of code into a malicious file with a &amp;lt;code&amp;gt;.php&amp;lt;/code&amp;gt; extension on the [[web server]] that is running [[PHP]], the attacker can issue commands, for example reading the &amp;lt;code&amp;gt;[[Passwd#Password file|/etc/passwd]]&amp;lt;/code&amp;gt; file, through a web browser using the following [[URL|Uniform Resource Locator]] if the web shell was located at &amp;lt;code&amp;gt;/uploads/webshell.php&amp;lt;/code&amp;gt;:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;https://example.com/uploads/webshell.php?x=cat%20%2Fetc%2Fpasswd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above request will take the value of the &amp;lt;code&amp;gt;x&amp;lt;/code&amp;gt; URL parameter, decode the URL it and send the following [[Bash (Unix shell)|Bash]] command:&lt;br /&gt;
 &amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/passwd&amp;lt;/source&amp;gt;&lt;br /&gt;
If the permissions of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file allow viewing the file, the web server will send the contents of &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; to the [[Web browser|browser]] and the browser will then display the contents of the &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; file or any other file the attacker wishes to view.&lt;br /&gt;
&lt;br /&gt;
This attack could have been prevented if the file permissions did not allow viewing the file or if the [[Shell (computing)|shell]] functions of [[PHP]] were disabled so that arbitrary shell commands cannot be executed from PHP.&lt;br /&gt;
&lt;br /&gt;
Other malicious actions are able to be executed by attackers with the web shell, such as replacing the contents of a file on the [[web server]]. For example, the [[Bash (Unix shell)|Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline&amp;gt;echo Hijacked page contents &amp;gt; index.php&amp;lt;/source&amp;gt; could be used to replace the contents of the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the text &amp;quot;Hijacked page contents&amp;quot;, which is one way a web page could be defaced, or create the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; file with the contents if the file does not exist. Attackers can also use the [[Bash]] command &amp;lt;source lang=&amp;quot;bash&amp;quot; inline&amp;gt;rm&amp;lt;/source&amp;gt; to delete files on the web server.&lt;br /&gt;
&lt;br /&gt;
==Prevention and mitigation==&lt;br /&gt;
Installation of a web shell is commonly accomplished through web application vulnerabilities or configuration weaknesses. Therefore, removal of these vulnerabilities are important to avoid potential compromisation of a web server&amp;lt;br&amp;gt;&lt;br /&gt;
The following are security measures for preventing the installation of a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;/&amp;gt;&lt;br /&gt;
* Regularly update the applications and the host servers&#039;s [[operating system]] to ensure protection against known [[Software bug|bugs]]&lt;br /&gt;
* Deploy [[DMZ (computing)|demilitarized zone]] (DMZ) between the web facing servers and the internal networks&lt;br /&gt;
* Secure configuration of the web server&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* Unnecessary services and [[Port (computer networking)|ports]] should be closed/blocked&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* Employ user input validation to restrict local and [[File inclusion vulnerability|remote file inclusion vulnerabilities]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* Use a [[reverse proxy]] service to restrict the administrative URL&#039;s to known legitimate ones &amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* Frequent vulnerability scan to detect areas of risk and conduct regular [[Computer virus|virus]] signature checks (this method does not protect against [[Zero-day (computing)|zero day attacks]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;)&lt;br /&gt;
*Deploy a web application [[Firewall (computing)|firewall]]&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
* Disable directory browsing&lt;br /&gt;
* Not using default login credentials&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Detection==&lt;br /&gt;
The ease of modification of a web shell makes it considerably hard to detect by system administrators, because it is equally not easy for programs developed with the aim of detecting [[Computer virus|viruses]]. For example, [[Antivirus software|anti-virus]] products sometimes produce poor results in detecting web shells.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;&amp;gt;{{cite web|url=https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html|title=Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I|author=|date=|website=FireEye|accessdate=20 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
The following may be indicators that a web server has been infected by a web shell:&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;auto&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abnormal high site usage (due to potential uploading and downloading activity by the attacker);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;/&amp;gt;&lt;br /&gt;
Files with an unusual timestamp (e.g., more recent than the last time the files were modified.);&amp;lt;ref name=&amp;quot;fireeye.com&amp;quot;/&amp;gt;&lt;br /&gt;
Suspicious files in Internet-accessible locations (web root);&lt;br /&gt;
Files containing references to suspicious keywords such as cmd.exe or eval;&lt;br /&gt;
Unexpected connections in server logs&lt;br /&gt;
&lt;br /&gt;
For example: A file type generating anomalous network traffic (e.g., a [[JPEG|JPG]] file making requests with POST parameters);&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;https://ws680.nist.gov/publication/get_pdf.cfm?pub_id=901146&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.networkworld.com/article/3085141/network-security/five-signs-an-attacker-is-already-in-your-network.html|title=Five signs an attacker is already in your network|first=Kasey Cross, Senior Product Manager|last=LightCyber|date=16 June 2016|website=Network World|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web | url=https://insights.sei.cmu.edu/sei_blog/2016/09/traffic-analysis-for-network-security-two-approaches-for-going-beyond-network-flow-data.html | title=Traffic Analysis for Network Security: Two Approaches for Going Beyond Network Flow Data}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
Suspicious logins originating from internal subnets to [[DMZ (computing)|DMZ]] servers and vice versa.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Attackers can also hide web shell logins in fake [[HTTP error|error pages]].&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://www.bleepingcomputer.com/news/security/hackers-hiding-web-shell-logins-in-fake-http-error-pages/|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=BleepingComputer|accessdate=21 December 2018}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;https://threatravens.com/hackers-hiding-web-shell-logins-in-fake-http-error-pages/&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://cyware.com/news/hackers-hiding-web-shell-logins-in-fake-http-error-pages-f9f1b47e|title=Hackers Hiding Web Shell Logins in Fake HTTP Error Pages|website=cyware.com|accessdate=22 December 2018}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Often, web shells will be used to spread [[malware]] onto a server and the [[search engines]] are able to see it. Attackers are known to alter the [[.htaccess]] files on the server to redirect [[Web search engine|search engine]] requests to the [[Web page|webpage]] with [[malware]] or [[Spamming|spam]]. Many web shells check the [[User agent|user-agent]] and the content presented to the [[search engine spider]] is different from that presented to the user&#039;s browser. To find a shell a [[User agent|user-agent]] change to one of the search engine bots is usually required. Once the shell is detected, it can be deleted easily.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performing frequency analysis on the web server&#039;s access logs could indicate the location of a web shell. Most legitimate visits will have different [[User agent|user-agent]]s and [[HTTP referer|referrers (referers)]], whereas a web shell is only visited by the attacker, therefore have very few variants of user-agent strings.&amp;lt;ref name=&amp;quot;us-cert.gov&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
*[[Backdoor (computing)]]&lt;br /&gt;
*[[Cyberwarfare]]&lt;br /&gt;
*[[Internet security]]&lt;br /&gt;
*[[Network security]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
{{Malware}}&lt;br /&gt;
{{Authority control}}&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
[[Category:Web security exploits]]&lt;br /&gt;
[[Category:Hacking (computer security)]]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
{{Source Wikipedia}}&lt;/div&gt;</summary>
		<author><name>Drive</name></author>
	</entry>
	<entry>
		<id>https://en.everybodywiki.com/index.php?title=File:Drive-increaser-llc.jpeg&amp;diff=299518</id>
		<title>File:Drive-increaser-llc.jpeg</title>
		<link rel="alternate" type="text/html" href="https://en.everybodywiki.com/index.php?title=File:Drive-increaser-llc.jpeg&amp;diff=299518"/>
		<updated>2019-01-25T06:33:53Z</updated>

		<summary type="html">&lt;p&gt;Drive: Ultimate Drive Increaser Software is a free storage increaser program that utilizes a Wizard (software) to increase the storage of FAT file sys devices.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Ultimate Drive Increaser Software is a free storage increaser program that utilizes a Wizard (software) to increase the storage of FAT file sys devices.&lt;/div&gt;</summary>
		<author><name>Drive</name></author>
	</entry>
</feed>