Web applications are often the majority of what we see exposed during an external network assessment and present an enormous attack surface. Use this file when the shell comes from a web upload or web application execution path.

A web shell is a browser-based shell session we can use to interact with the underlying OS of a web server. Usually involves some some form file upload vulnerability that gives remote code execution.

File uploads will often be restricted. We can sometimes bypass this by changing the content-type in the request packet to a type that is validated by the server.

It is important to note that web applications sometimes automatically delete files after a pre-defined period. Also, limited OS activity and usually greater chance of leaving behind proof that we were successful in the attack.

Laudanum ASPX Shell

Laudanum is a repo of ready-made files that can be used to be used to inject onto a victim and receive back access via a reverse shell.

Active Server Page Extended (ASPX) is a file extension written for Microsoft’s ASP.NET Framework. Web form pages written with this framework can be generated for users to input data. The server will convert this into HTML.

Antak is a type of web shell developped built in ASP.Net. Remember to edit the password of the shell to access it remotely.

# copy a shell from the laudanum directory for modification
cp /usr/share/laudanum/aspx/shell.aspx /home/tester/demo.aspx

PHP Web Shells

Hypertext Preprocessor or PHP is a server-side programming language. Meaning it processes code and commands on the server-side, therefore allowing us to have payloads run on the server.