Get the App
SLTechnology News&Howtos  ›  Development  › 

How to identify the simple back door of inspection-free PHP

Shulou Source: shulou.com Published: 2022-06-03 09:02:49 09月30日 Update

This article introduces the relevant knowledge of "how to identify a simple inspection-free PHP back door". In the operation of actual cases, many people will encounter such a dilemma, so let the editor lead you to learn how to deal with these situations. I hope you can read it carefully and be able to achieve something!

One of the most common sentences may be written like this.

Or like this.

Tudouya gave [a construction skill] on FREEBUF to make use of

The copy code is as follows:

Construction generation, of course, is too intuitive to write like this.

The copy code is as follows:

Then fill in some ordinary code for camouflage, and a simple "kill-free" shell sample appears

Let's take a look at the back door of the php, which claims to be the simplest test-free kill in history.

Go directly to the code:

Password page

Recently captured a webshell sample based on PHP, its ingenious code dynamic generation, creepy own page camouflage, let us feel a lot of fun in the process of analyzing this sample. Next, let's enjoy this strange Webshell together.

The Webshell code is as follows:

Tags: Code backdoor content generation one sentence Trojan sample picture file next function pervert command malicious more feature knowledge coding procedure detection Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MySQL vpn MariaDB macOS Redmi