from: https://zhuanlan.zhihu.com/p/550150061 __FILE__是PHP的一个魔术常量,它会返回当前执行PHP脚本的完整路径和文件名,我们利用substr()函数逆着截取,就能获得system再利用变量做函数的方式,打断了污点追踪的过程,进行命令执行,也可以成功bypass掉牧云引擎。 usage: file:xxx.php post: body==>1=whoami |
||
---|---|---|
.github | ||
138shell | ||
antSword | ||
antSword-shells | ||
AntSwordProject | ||
asp | ||
aspx | ||
b4tm4n-toolz | ||
Backdoor Dev Shells | ||
backlion | ||
bartblaze | ||
Behinder | ||
BlackArch | ||
caidao-shell | ||
content | ||
DeEpinGh0st | ||
docs | ||
drag | ||
fuzzdb-webshell | ||
Godzilla | ||
java/字节码增强型 | ||
JohnTroony | ||
JoyChou93 | ||
jsp | ||
jspx | ||
LandGrey | ||
lcatro | ||
lhlsec | ||
malwares | ||
msmap | ||
net-friend | ||
nodejs | ||
oneoneplus | ||
other | ||
php | ||
pl | ||
py | ||
rec | ||
tanjiti | ||
tdifg | ||
threedr3am | ||
vnhacker1337 | ||
WangYihang | ||
web-malware-collection-13-06-2012 | ||
webshellpub | ||
wsMemShell | ||
www-7jyewu-cn | ||
xakep-shells | ||
xl7dev | ||
ysrc | ||
.gitmodules | ||
_config.yml | ||
bt_yincang_shell.md | ||
bypass.md | ||
LICENSE | ||
other shell repository.md | ||
php_niu_3.php | ||
proxy.py | ||
README.md | ||
README_EN.md | ||
SECURITY.md | ||
几种实战成功过的webshell的免杀方式.md |
webshell 简体中文
This is a webshell collection project
Give someone a rose, there is a fragrance in your hand
if you download this project, please also submit a shell
This project covers various common scripts
Such as: asp, aspx, php, jsp, pl, py
If you submit a webshell, please do not change the name and password
Note: There is no guarantee whether there could be a backdoor in a shell, but I will never add a backdoor deliberately when uploading by myself
Please don’t add a backdoor if you submit
If you find a backdoor code, please create an issue immediately!
The tools provided by this project are forbidden to engage in illegal activities. This project is for testing purposes only. All the consequences caused by it have nothing to do with me.
Expanding a project
- webshell-venom
- Kill-free webshell unlimited generation tool
- Kill-free webshell unlimited generation tool (Kill-free one sentence generation|Kill-free D shield|Kill-free security dog guard God Hippo check and kill everything waf)
- Author : yzddmr6
- Please identify yourself
other webshell project (update 2020-09-14)
- xl7dev/WebShell
- JohnTroony/php-webshells
- BlackArch/webshells
- LandGrey/webshell-detect-bypass
- JoyChou93/webshell
- bartblaze/PHP-backdoors
- WangYihang/Webshell-Sniper
- threedr3am/JSP-Webshells
- DeEpinGh0st/PHP-bypass-collection
- lcatro/PHP-WebShell-Bypass-WAF
- ysrc/webshell-sample
- tanjiti/webshellSample
- webshellpub/awsome-webshell
- tdifg/WebShell
- malwares/WebShell
- lhlsec/webshell
- oneoneplus/webshell
- vnhacker1337/Webshell
- backlion/webshell
By the way, we are pushing a wave of website management tools
- Chinese Kitchen Knife
- Cknife
- Altman
- xise
- Weevely
- quasibot
- Webshell-Sniper
- 蚁剑 antSword
- 冰蝎 Behinder
- webacoo
- 哥斯拉 Godzilla
- PhpSploit
- The above rankings are in no particular order
Author :tennc
http://tennc.github.io/webshell
license : GPL v3
Download link
Check github releases. Latest:
https://github.com/tennc/webshell/releases