Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.(Citation: volexity_0day_sophos_FW) In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Web Shell Detection via Server Behavior and File Execution Chains
is blocked by Disable or Remove Feature or Program
is blocked by User Account Management
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Separation of Duties (SoD)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch