WebShell Invasion of Network Security

Source: Internet
Author: User
Keywords webshell webshell definition webshell detection
1. What is WebShell?

As the name implies, "web"-obviously requires the server to open web services, and "shell"-gains some degree of operational authority over the server.

Webshell is often referred to as an anonymous user (intruder) who has a certain degree of authority to operate the WEB server through the WEB service port. Because most of it appears in the form of web scripts, it is also called a website backdoor tool.

2. What is the role of WebShell?

On the one hand, webshell is often used by webmasters for website management, server management, etc. According to different FSO permissions, it can be used to edit web scripts online, upload and download files, view databases, and execute arbitrary program commands.

On the other hand, it is used by intruders to achieve the purpose of controlling the website server. These web page scripts are often called WEB.

Script Trojans, currently popular asp or php Trojans, and script Trojans based on .NET.

3. WebShell's concealment

Some malicious webpage scripts can be nested and run in normal webpages, and are not easy to be killed.

WebShell can traverse the server firewall. Since the data exchanged with the controlled server or remote host is transmitted through port 80, it will not be intercepted by the firewall. In addition, using webshell generally does not leave a record in the system log, but only leaves some data submission records in the web log of the website. It is difficult for inexperienced administrators to see the trace of the intrusion.

4. How to prevent malicious backdoors?

To fundamentally solve the security problem of dynamic web scripts, to prevent injection, anti-riot library, anti-COOKIES deception, anti-cross-site attacks, etc., be sure to configure the server FSO permissions.
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.