RE: snodew2, PHP root reverse shell backdoor 04-26-2020, 09:52 AM
#3
(04-26-2020, 09:42 AM)mothered Wrote: Very Impressive Indeed, and quite damaging for someone with malicious Intent.
Did you write this entirely on your own?
yeah, i did. albeit i used some code from my previous projects, and in creating this, discovered more that i could add to my current rootkit project, i.e. only breaking ss if there's a hidden port being used at the time of the calling process being launched.
i'm not sure what else i can add to it... but i don't want to add too much to this. my main focus really, in this project, is security i guess, when it comes to the iswww() function. since in the previous iteration of this project i believe it was quite easy to 'pretend' to be the target service user so that you can see all of the hidden rootkit files.
i was thinking of using one of those public web shells with fully fledged ui, for the php script... but idk. i think those are pretty lame, but my argument against that atm is that they're accessible. maybe i could have a host of scripts to choose from, at some point. that's an idea for me to note down somewhere.
additionally, i need to look a bit more into how the services write their access logs. i've hooked write() so that it breaks itself upon detecting the php script's filename in its buf, but that's all i've done in an effort to prevent log writing when viewing the php script on the server after installation. kinda sucky, as far as 'anti-logging' goes.
(This post was last modified: 04-26-2020, 09:56 AM by tranquil.)
fuck ya chicken strips
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)