January 2019
Intermediate to advanced
548 pages
12h 7m
English
Once a web server and its services have been compromised, it is important to ensure that secure access can be maintained. This is usually accomplished with the aid of a web shell, a small program that provides stealth backdoor access and allows the use of system commands to facilitate post-exploitation activities.
Kali comes with several web shells; here, we will use a popular PHP web shell called Weevely. For other technologies, attackers might refer to http://webshell-archive.org/.
Weevely simulates a Telnet session and allows the tester or attacker to take advantage of more than 30 modules for post-exploitation tasks, including the following:
Read now
Unlock full access