-
06-09-2011, 08:00 AM #1Garage Hyper Addict


- Join Date
- Jul 2010
- Location
- irc.freenode.net #g4h
- Posts
- 644
- Thanks
- 140
- Thanked 270 Times in 109 Posts
Web Backdoor Shell Detection on Servers
Hi Guys,
I found couple of good scripts which could be helpful for system admins to detect the presence of web backdoor shells on their servers. So just sharing them here:
1. Web Shell Detection Using NeoPI - A python Script
(https://github.com/Neohapsis/NeoPI)
2. PHP Shell Scanner - A perl Script
3. PHP script to find malicious code on a hacked server - A PHP Script
(http://25yearsofprogramming.com/blog/2010/20100315.htm)
I've tested the 1st and 2nd and found them good. 3rd one probably needs some customization.
Btw for a quick one, the following grep command can also be used:
The command says:Code:grep -RPl --include=*.{php,txt,asp} "(passthru|shell_exec|system|phpinfo|base64_decode|chmod|mkdir|fopen|fclose|readfile) *\(" /var/www/
1. Check files with extensions php or txt or asp only. You can add in more.
2. The pattern matching strings would be "passthru", shell_exec and so on. You can add/remove patterns.
3. The directory from where a recursive search has to be started. In this case it is /var/www/
RgdsLast edited by b0nd; 06-30-2011 at 07:21 AM. Reason: typo
[*] To follow the path: look to the master, follow the master, walk with the master, see through the master,
------> become the master!!! <------
[*] Everyone has a will to WIN but very few have the will to prepare to WIN
[*] Invest yourself in everything you do, there's fun in being serious
-
The Following 13 Users Say Thank You to b0nd For This Useful Post:
"vinnu" (06-09-2011), 41.w4r10r (06-13-2011), Anant Shrivastava (06-09-2011), AnArKI (06-09-2011), d4rkd4wn (06-09-2011), fb1h2s (06-09-2011), materaj (06-10-2011), neo (06-09-2011), prashant_uniyal (06-09-2011), s1ayer (07-17-2011), silentph33r (06-09-2011), the_empty (06-10-2011), [s] (06-11-2011)
-
06-10-2011, 06:55 AM #2Garage Newcomer
- Join Date
- Jun 2011
- Location
- My blog: http://r00tsec.blogspot.com
- Posts
- 1
- Thanks
- 1
- Thanked 0 Times in 0 Posts
Great post, I will share this in my blog. Thank you for this post.
-
06-10-2011, 03:32 PM #3Security Researcher

- Join Date
- May 2011
- Location
- Pune, Maharashtra, India
- Posts
- 226
- Blog Entries
- 1
- Thanks
- 75
- Thanked 91 Times in 50 Posts
either the top post is copied or this article is coped to pentestit without any credit
http://www.pentestit.com/2011/06/10/...shell-servers/Website :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Blog :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-
06-13-2011, 08:28 AM #4Garage Hyper Addict


- Join Date
- Jul 2010
- Location
- irc.freenode.net #g4h
- Posts
- 644
- Thanks
- 140
- Thanked 270 Times in 109 Posts
err...
1. No question of copying in the top post as I said I found something over net and shared here. Would I copy without giving credit?
2. Yes, the post has been copied as such from here and posted on pentest.it but I can see the credit has been given to me there. "Fast and easy thanks to B0nd for sharing it."
Probably you overlooked that part or the author edited it later on.
Rgds[*] To follow the path: look to the master, follow the master, walk with the master, see through the master,
------> become the master!!! <------
[*] Everyone has a will to WIN but very few have the will to prepare to WIN
[*] Invest yourself in everything you do, there's fun in being serious
-
The Following User Says Thank You to b0nd For This Useful Post:
"vinnu" (07-18-2011)
-
06-13-2011, 08:50 AM #5Security Researcher

- Join Date
- May 2011
- Location
- Pune, Maharashtra, India
- Posts
- 226
- Blog Entries
- 1
- Thanks
- 75
- Thanked 91 Times in 50 Posts
Website :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Blog :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-
06-13-2011, 09:38 AM #6Super Administrator


- Join Date
- Jul 2010
- Location
- London
- Posts
- 501
- Blog Entries
- 1
- Thanks
- 180
- Thanked 169 Times in 86 Posts
I think pentestit picked it from our twitter feeds.
-
06-13-2011, 11:42 AM #7Administrator
- Join Date
- Jul 2010
- Location
- Above Sea level
- Posts
- 163
- Blog Entries
- 1
- Thanks
- 8
- Thanked 71 Times in 31 Posts
dont u think pentestit could have included g4g post link has the reference
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Hire a Hacker by the Night and Hire a Chief Security Officer (CSO) by the Day.
-
07-16-2011, 05:46 PM #8Laurel421Guest
either the top post is copied
-
07-16-2011, 06:52 PM #9Garage Hyper Addict


- Join Date
- Jul 2010
- Location
- irc.freenode.net #g4h
- Posts
- 644
- Thanks
- 140
- Thanked 270 Times in 109 Posts
Enough is enough. Anyone utter a single word me copying the top post and will find himself landing in ban list.
First and last warning to you Laurel421. Just seen couple of more sense less posts by you.[*] To follow the path: look to the master, follow the master, walk with the master, see through the master,
------> become the master!!! <------
[*] Everyone has a will to WIN but very few have the will to prepare to WIN
[*] Invest yourself in everything you do, there's fun in being serious
-
07-16-2011, 07:28 PM #10Super Administrator


- Join Date
- Jul 2010
- Location
- London
- Posts
- 501
- Blog Entries
- 1
- Thanks
- 180
- Thanked 169 Times in 86 Posts
@Laurel421 watch ur words
LinkBacks (?)
-
SecWiki
Refback This thread10-27-2012, 12:19 PM -
BSS-12-S3-Int3: Internship Project: Web Shell Detector &bull; View topic - Some websites for research
Refback This thread08-11-2012, 09:23 PM -
08-03-2012, 11:53 AM
-
03-25-2012, 01:00 AM



LinkBack URL
About LinkBacks



Reply With Quote

i am a secret hacker with all...
Yesterday, 09:35 PM in Noobs Corner