What is a web shell?
A web shell is a malicious script written using commonly used web application languages such as PHP, JSP, or ASP. They provide an attacker with a easy way to attack a compromised web server via web-based vulnerabilities, and once installed on a web server’s operating system, the web shell’s facilitate remote administration.
A web shell can allow threat actors to modify files on the web server and even access the root directory of the web server.
Web shells are a tactic used by threat actors to maintain persistence T1505.003
data:image/s3,"s3://crabby-images/e7346/e7346a869240a52a0ade08fe258cdd1143478999" alt="MITRE Attack tactic on web shells"
How do attackers use a web shell?
data:image/s3,"s3://crabby-images/61d0f/61d0ff126c843e1d54a8b5272b761884ee5e8eab" alt="Image of a web shell"
Threat attackers do a search for servers which are vulnerable to web shell attacks. On discovering a vulnerable web server threat actors launch a web shell attack before the victim becomes alert and patches the vulnerability. The attacker usually takes advantage of common web page vulnerabilities such as SQL injection, remote file inclusion (RFI), and cross-site scripting (XSS)
The web shell runs on web server software with limited user permissions. Using the web shell, attackers attempt to perform privilege escalation by exploiting local vulnerabilities in the system to gain root access, enabling them to take complete control of the server.
Characteristics of some the Web Shells are shown below
Shreshta Threat Intelligence team has decrypted some web shells, and snippets of the characteristics of the web shell are shown below.
Webshell #1 0byte v2 Shell
data:image/s3,"s3://crabby-images/b837b/b837b4228603b538dcb8e0060474c3618993ede1" alt=""
Figure 1 – Screenshot of the decrypted code of the 0byte v2 web shell
The code is designed to execute shell commands using various PHP functions such as system, exec, passthru, and shell_exec. It incorporates error and log suppression functions to avoid detection.
data:image/s3,"s3://crabby-images/7d303/7d303a880bf047e8a37cea2c65a42569a265d7bf" alt=""
Figure 2- Screenshot of code that allows the attacker to download the data
The above code snippet allows the attacker to download files from the server by specifying the file path in the $_GET[‘file’] parameter
data:image/s3,"s3://crabby-images/6bd3e/6bd3e72c60da061836207e282725c92b00d47e6a" alt=""
Figure 3 – Screenshot of the snippet of the reverse shell code
The above code echoes HTML to display a form for configuring and executing a reverse shell by using the POST method.
data:image/s3,"s3://crabby-images/b99ac/b99ac3133462fd27ac730a212f5c7fdd91ed4589" alt=""
data:image/s3,"s3://crabby-images/2ac9f/2ac9f13478c4ed3eb8da3a570105cf8a3cb6e41a" alt=""
Figure 4 – Screenshot of the encrypted and decrypted code
This part of the code is used for tracking or reporting the usage of the backdoor to a remote server.
Webshell #2 0x Shell
data:image/s3,"s3://crabby-images/09bae/09bae5867927643bcbac58db61d6ccf0301745db" alt=""
Figure 5 – Screenshot of code snippet defines various parameters
The parameter includes the shell name, slogan, version, and security bypass setting. It also incorporates bot protection, preventing it from being cached or crawled, along with error suppression.
data:image/s3,"s3://crabby-images/03f53/03f535011093798bf12c07c5fd8e494a4d8aa606" alt=""
Figure 6 – Screenshot of the code file scanner
This code tries to identify popular web application configuration files (e.g., WordPress, Joomla, Magento) based on file paths.
data:image/s3,"s3://crabby-images/6569c/6569c4e4a9d15b51e518999bea1bf8087534a63d" alt=""
Figure 7 – Screenshot of the code handling file download and upload
data:image/s3,"s3://crabby-images/bfbba/bfbbae3081ccbc9e3e213ee82563f866166e2889" alt=""
Figure 8 – Screenshot of tool creation function
The code downloads tools from external URLs and stores them in the “0x1” directory.
data:image/s3,"s3://crabby-images/e5d6b/e5d6bcadaae193c7e6baf230257ede5d9b3c98dd" alt=""
Figure 9 – Screenshot of code attempting to extract passwords of web applications from their configuration files.
data:image/s3,"s3://crabby-images/0b52c/0b52c61f7fcd0994ac27e8d40875aec91efba3f2" alt=""
data:image/s3,"s3://crabby-images/583fc/583fcf80376c63e228c509ad2d78d10dd55db568" alt=""
Figure 10 – Screenshot of base64 encrypted Perl script that opens a reverse shell
Reverse shell also known as a remote shell or “connect-back shell,” which takes advantage of the target system’s vulnerabilities to initiate a shell session and then access the victim’s computer
data:image/s3,"s3://crabby-images/7be33/7be33a33bf647ddd771d6eeafe3c6c5c77913c01" alt=""
Figure 11 – Screenshot of the code extracts information from the listed configuration path
The code extracts information from specified configuration files on the web server. The extracted information is then either saved in a new file or symlinked, depending on the value of the ‘tipe’ parameter
data:image/s3,"s3://crabby-images/5e448/5e44887b37fdd377cab288656d92cc54578efc43" alt=""
Figure 12 – Screenshot of the code having the self-remove option
Web shell #3 1337 3YP455 Shell
data:image/s3,"s3://crabby-images/711b6/711b605c2f055f9aa2b5135ccf2c3a3bb8bd4f00" alt=""
Figure 13 – Screenshot of the code for error suppression and initialisation of the session
data:image/s3,"s3://crabby-images/e5f22/e5f22d554d8d34bba8746cc0d7466f0a7dbfe6a9" alt=""
Figure 14 – Screenshot of the file upload functionality
Web shell #4 2018 WSO Shell
data:image/s3,"s3://crabby-images/14ded/14ded4454f3bf7f3f58fd02f27c766f8a4545ee7" alt=""
Figure 15 – Screenshot of Encrypted web shell using multistage encryption
data:image/s3,"s3://crabby-images/da101/da101999520c28582ff2aa300e7b377e9a682c73" alt=""
Figure 16 – Screenshot depicting error reporting and configuration settings
data:image/s3,"s3://crabby-images/359fe/359fe9f61d4a381bb2057fdd68fdc2c21d196c93" alt=""
Figure 17 – Screenshot of the hard login function with bot protection
It incorporates bot protection, preventing it from being cached or crawled by the listed user agents
data:image/s3,"s3://crabby-images/a66f2/a66f2566b02a9d918fb64ddc4c04a50cf6a11298" alt=""
Figure 18 – Screenshot of the code using exploit-db
The $explink variable constructs a URL for searching the Exploit Database for exploits related to the server’s operating system and kernel version
data:image/s3,"s3://crabby-images/8a50d/8a50d2152bbddfc5552f93c3251823bfa5e8efaa" alt=""
data:image/s3,"s3://crabby-images/595a6/595a6dad537c9cb2e2653109ed1cac1b022f825e" alt=""
Figure 19 – Screenshot of the encrypted and decrypted code
The code creates an email ($xd) with server details and sends it to the specified address ($hex) using the mail function
data:image/s3,"s3://crabby-images/8a1ad/8a1ada1f7b1516a7efb548282ebe6e6a91dd3753" alt=""
Figure 20 – The encrypted code of the cPanel information grabber
data:image/s3,"s3://crabby-images/10efe/10efef3c9bd19e795be2512d4432a7f0daf360ab" alt=""
Figure 21 – Screenshot of the heading of the code with error suppression
data:image/s3,"s3://crabby-images/6f6da/6f6daffb4797be30b4df279294982f2987e267d5" alt=""
Figure 22 – Screenshot of the code exfiltrating encoded information to a C&C
data:image/s3,"s3://crabby-images/22cc8/22cc8e7c0347f6c17036a4cccd0fe140ad9d8207" alt=""
Figure 23 – Screenshot of the encrypted code that scans the “/home” directory
This script scans and displays the “/home” directory for possible readable and writable directories
data:image/s3,"s3://crabby-images/92434/92434bb54ff44d630fab8623610c324e05b380eb" alt=""
Figure 24 – Screenshot of the code having the self-remove option
Web shell #5 22XC Mini Shell
data:image/s3,"s3://crabby-images/86af5/86af5120d702550234b47c1979cac41f4655522a" alt=""
Figure 25 – Screenshot of the session and security settings
The PHP script is modified using “ini_set” to suppress errors, clear stat cache, and disable error logging/display.
data:image/s3,"s3://crabby-images/7c87a/7c87a956f34e7397e05a9bcf98ea79d3ab301e24" alt=""
Figure 26 – Screenshot of the hard login function with bot protection
It incorporates bot protection, preventing it from being cached or crawled by the listed user agents
data:image/s3,"s3://crabby-images/2a029/2a029250894746e9076e84ed460cb3136715b429" alt=""
Figure 27 – Screenshot of code that allows the attacker to download the data
data:image/s3,"s3://crabby-images/a37e2/a37e2b6d6215c8a7c17f5af1d62bf0014411fdc3" alt=""
Figure 28 – Screenshot of code that is related to the creation and execution of a ransomware script
Web shell #6 22XploiterCrew Shell
data:image/s3,"s3://crabby-images/b9854/b9854680deaa6d5c3048879bcfb5aee003ea2ba0" alt=""
Figure 29 – Screenshot of the meta tags of the 22XploiterCrew Shell
data:image/s3,"s3://crabby-images/3d24b/3d24b0eb7db6cf85c5347d1e36a3b13046cfc5f1" alt=""
Figure 30 – Screenshot of the script extracting various details of the server and sending it to a C&C
data:image/s3,"s3://crabby-images/40394/403943499b224b7ec2563b326d16b060f8948a68" alt=""
Figure 31 – Screenshot of the code handling file uploads
data:image/s3,"s3://crabby-images/0204a/0204a61afa8e66aef2348190580c95e7bf0fad6e" alt=""
Figure 32 – Screenshot of the code handling website defacement
Website defacement is an attack on a website that changes the visual appearance of a website or a web page
data:image/s3,"s3://crabby-images/2699c/2699c8dfcaf41302b7e74579fdfa470688396697" alt=""
Figure 33 – Screenshot of the code checking for and installing Adminer
The web shell checks for the presence of Adminer on the server; if it is not found, the script attempts to install it.
data:image/s3,"s3://crabby-images/2b71d/2b71d44e9db8e037f2f8a5cf60a681aacdf6f712" alt=""
Figure 34 – Screenshot of the code handling the reset of cPanel’s credentials.
Web shell #7 404 Not Found Mini Shell
data:image/s3,"s3://crabby-images/0db55/0db558d63c8325ccc75be652f81da1d237e614b0" alt=""
Figure 35 – Screenshot of the file upload functionality
data:image/s3,"s3://crabby-images/24c53/24c53a0307350a83a2d55812a6a52b258c92b41d" alt=""
Figure 36 – Screenshot of the file download functionality
Web shell #8 404 Not Found Mini Shell
data:image/s3,"s3://crabby-images/563a8/563a8c29523b1199c631dfdbd786d40c57a3ae8e" alt=""
Figure 37 – Screenshot of the code searching for the particular OS vulnerability on “Milw0rm” website
data:image/s3,"s3://crabby-images/296f1/296f16d99ac3982f9cb5f9147544243e344fc1fb" alt=""
Figure 38 – Screenshot of the code with a list of arrays
The arrays are listed to verify the presence of databases, security tools, and downloading capabilities.
data:image/s3,"s3://crabby-images/c81b2/c81b2e37e1094600e6074f002051115f492915cd" alt=""
Figure 39 – Screenshot of the file upload functionality
data:image/s3,"s3://crabby-images/59522/595224a48c3721d44987248b6749a59095532df6" alt=""
Figure 40 – Screenshot of the code having the log-out option
data:image/s3,"s3://crabby-images/df0e0/df0e0483c2205e9f3256a89e13d8259abcc06c72" alt=""
Figure 41 – Screenshot of the code having the self-remove option
data:image/s3,"s3://crabby-images/63e5b/63e5b00a3790ab4bcc4156679f73e9ac5f282510" alt=""
Figure 42 – Screenshot of the code for the brute-force function
The PHP script performs brute-force attacks on different types of servers, specifically for FTP, MySQL, and PostgreSQL protocols.
data:image/s3,"s3://crabby-images/aeb42/aeb4236e4aeeebcc22085d888b3e42d6d5cf8816" alt=""
data:image/s3,"s3://crabby-images/0a295/0a2951e66ffdfe616324f022f8c1787436204189" alt=""
Figure 43 – Screenshot of the script that compiles and executes a C program backdoor “$back_connect_c”
The compilation and the execution of the code happens in the background
data:image/s3,"s3://crabby-images/b3b00/b3b00cca8ace62b21b77443d2bf0e1fdedb0ce97" alt=""
data:image/s3,"s3://crabby-images/81567/8156713c99b86d1a6d37b6a6f338b09864452d7b" alt=""
Figure 44 – Screenshot of the script that compiles and executes a Perl script backdoor “$back_connect_p”
The compilation and the execution of the code happens in the background
Web shell #9 407 Mini Shell
data:image/s3,"s3://crabby-images/02127/02127600fda807cb8734346117cfbacfc1dffe3b" alt=""
Figure 45 – Screenshot of the hard login function with bot protection
data:image/s3,"s3://crabby-images/23e67/23e673186d3fe6a804c90b5e3a2fc2dd9f732225" alt=""
Figure 46 – Screenshot of the file upload functionality
Web shell #10 51mp3L Web Backdoor
data:image/s3,"s3://crabby-images/217cf/217cf3e37daad71ffced2e60f53a28a151585a44" alt=""
Figure 47 – Screenshot of the file upload functionality
data:image/s3,"s3://crabby-images/5d3db/5d3dba8eae5f606e6211e2e0c53d63d0f2b077c4" alt=""
Figure 48 – Screenshot of the code sending information to an external server
Web shell marketplace
Web shells are readily available on the Internet, accessible through platforms such as Telegram, GitHub etc. Some of them are shown below.
Telegram chat #1 offers free downloads of web shells
data:image/s3,"s3://crabby-images/151b5/151b5eefa32ce5063334e0ba604666ff3b9f3abb" alt=""
Figure 49 – The Telegram chatroom offers free downloads for web shells and hack tools
Telegram chat #2 offers free downloads of web shells
data:image/s3,"s3://crabby-images/df74c/df74cab67c496804cec401852ed545ff1c68fdde" alt=""
Figure 50 – The Telegram chatroom offers free downloads of the latest web shell.
Website #1 allows users to download webshells
data:image/s3,"s3://crabby-images/58e70/58e7098be39dd4a4f945e7e758e5706ab1fd7355" alt=""
Figure 51 – The website presents webshells with descriptions and offers free downloads
Website #2 allows users to download webshells
data:image/s3,"s3://crabby-images/cf017/cf0174afa3f1c1557998c69769767dbc1b9e4342" alt=""
Figure 52 – The website offers free downloads of webshells with various features
Website #3 allows users to download webshells
data:image/s3,"s3://crabby-images/aaca7/aaca7ca8f9a7b0a39062e322f9e165b13fa01865" alt=""
Figure 53 – The website provides free downloads of webshells along with an archive of past versions.
Safety Recommendations
- We recommend following the OWASP ( Open Worldwide Application Security Project) and adhere to their Top 10 safety recommendations to enhance cyber security measures
- Keep your systems software updated with the latest security patches
- Disable unwanted and outdated Content management software ( CMS ) plugins
- If not in use, disable the PHP functions such as exec(), shell_exec(), passthru(), system(), show_source(), proc_open(), pcntl_exec(), eval(), and assert() as they are used in web shell for code executions
- If your website/web application is using upload forms, make sure that they are secure and that they only allow listed file types to be uploaded
- Disable PHP execution in sensitive directories like images or uploads
- Do not blindly use code that you may find on online forums or websites
- Try to avoid installing third-party plugins.
- Deploy a web application firewall such as ModSecurity
- NSA Guidance on mitigating web shells
Conclusion
Despite their simplicity, web shells are a common way for attackers to gain the ability to run commands on a server remotely and avoid detection by hiding their “error logs”. They are easy to customise, flexible and require modest programming skills.
For a website or an application following bad security practices, they can be very damaging, leading to data exfiltration, installation of malware, and web page defacement.