Mastodon Mastodon Mastodon Mastodon

Web Shell

Updated: · CyberSecureFox Editorial Team

A web shell is a malicious script placed on a web server that lets an attacker run commands on that server remotely through ordinary HTTP requests.

How a web shell works

A web shell is a small file written in a language the server executes – PHP, ASP.NET (ASPX), JSP or Python. Once it sits in a web-accessible folder, the attacker opens its URL or sends specially crafted requests and the server executes the commands with the privileges of the web application. Some web shells are a single line of code, like the infamous China Chopper; others offer a full graphical interface with a file manager and database client.

Attackers plant web shells by exploiting file-upload flaws, remote code execution bugs or stolen admin credentials. In 2021 the ProxyLogon and ProxyShell vulnerabilities in Microsoft Exchange led to tens of thousands of servers being infected with web shells within days.

Why web shells are dangerous

A web shell is a backdoor that survives patching: even after the original vulnerability is fixed, the attacker can come back. From the server they steal data, move deeper into the network, install cryptominers or ransomware, or use the host as a relay. Their traffic blends into normal web requests, and MITRE ATT&CK lists web shells as a persistence technique (T1505.003).

How to detect and prevent web shells

  • Patch internet-facing applications quickly and restrict file uploads by type and location.
  • Monitor file integrity in web directories and alert on new script files.
  • Watch for web server processes (w3wp.exe, php-fpm, httpd) spawning shells such as cmd.exe or /bin/sh.
  • After any compromise, hunt for web shells as indicators of compromise before declaring the incident closed.
Synonyms:
webshell