Breaking News
You are here: Home / Programming / A look at PHP backdoor shells

A look at PHP backdoor shells

A backdoor shell can be a PHP, ASP, JSP, etc. piece of code which can be uploaded on a site to gain or retain access and some privileges on a website. Once uploaded, it allows the attacker to execute commands through the shell_exec () function, upload/delete/modify/download files from the web server, and many more. For defacers, it allows them to navigate easily to the directory of the public_html or /var/www and modify the index of the page.

In this write-up, we will be talking about PHP backdoor shells, how they work, how to detect them and remove them. Below is a simple PHP code that is very popular and is scattered all over the web (http://stackoverflow.com/questions/3115559/exploitable-php-functionshttp://shipcodex.blogspot.com/2012/01/simple-php-backdoor-shell.html). This code allows an attacker to execute *nix commands. For the full write up at

InfoSec Institute, check here:
http://resources.infosecinstitute.com/checking-out-backdoor-shells/

About FastFlux

Owner of ZeroSecurity, intrested in programming, malware analysis and penetration testing. If you are interested in joining the ZeroSecurity team please use the contact forum located above to contact us.
Scroll To Top
x
EmailEmail
PrintPrint
WP Socializer Aakash Web