Hunting Web Backdoors

Hunt planted webshells and backdoors across a web source tree — PHP first (also JSP, ASP, Node) — triaging a directory at scale, statically decoding obfuscation layers without ever executing the payload, finding append-infections and fake plugins, and treating known shell families as leads rather than verdicts. Use when a web server is suspected compromised, cleaning a hacked WordPress/Magento/CMS site, vetting a downloaded PHP codebase or plugin for hidden malicious code, or when a file contains eval on decoded input.

trilwu e426c5c 11.6 KB Updated

File contents

trilwu/secskills/tree/main/secskills-core/skills/hunting-web-backdoors commit e426c5c30f

Frequently asked questions

npx skillmds add trilwu/hunting-web-backdoors