⤷ Title: Day 77: Other shells
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 22:37:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #shell #bind_shell #webshell #penetration_testing
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 22:37:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #shell #bind_shell #webshell #penetration_testing
Medium
Day 77: Other shells
Web and bind shells
⤷ Title: SOC — How You Can Detect Web-Shells
════════════════════════
𐀪 Author: Suraj Singh
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 15:24:18 GMT
════════════════════════
⌗ Tags: #webshell #tryhackme_walkthrough #tryhackme
════════════════════════
𐀪 Author: Suraj Singh
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 15:24:18 GMT
════════════════════════
⌗ Tags: #webshell #tryhackme_walkthrough #tryhackme
Medium
SOC — How You Can Detect Web-Shells
A web shell is a malicious program uploaded to a target web server, enabling adversaries to execute commands remotely. It often serves as…
⤷ Title: From XSS to privesc in Wordpresss: Vulnerable plugins and Admin CSRF nonces to create a new Admin
════════════════════════
𐀪 Author: Rogercastefdez
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 13:36:55 GMT
════════════════════════
⌗ Tags: #webshell #xs #wordpress #csrf #cybersecurity
════════════════════════
𐀪 Author: Rogercastefdez
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 13:36:55 GMT
════════════════════════
⌗ Tags: #webshell #xs #wordpress #csrf #cybersecurity
Medium
From XSS to privesc in Wordpresss: Vulnerable plugins and Admin CSRF nonces to create a new Admin
Step 1: The Root Cause — Visitors Plugin Vulnerability
⤷ Title: Web Shells 101: Your First Step into Digital Backdoors (and How Not to Get Pwned!)
════════════════════════
𐀪 Author: Evilfeonix
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 05:42:05 GMT
════════════════════════
⌗ Tags: #webshell #hacking #backdoor
════════════════════════
𐀪 Author: Evilfeonix
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 05:42:05 GMT
════════════════════════
⌗ Tags: #webshell #hacking #backdoor
Medium
Web Shells 101: Your First Step into Digital Backdoors (and How Not to Get Pwned!)
Hello guy, am evilfeonix! The Digital Firebird.
⤷ Title: Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
Daily CyberSecurity
Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
Symantec exposed a Russian-aligned espionage campaign in Ukraine using LotL tactics. Attackers used a Sandworm-linked webshell (Localolive) and abused scheduled tasks to dump credentials and bypass Windows Defender.
⤷ Title: eJPT Lab Write-Up: Host & Network Penetration Testing: Exploitation CTF 3
════════════════════════
𐀪 Author: Ninadkarkhanis
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 09:39:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ejpt #webshell
════════════════════════
𐀪 Author: Ninadkarkhanis
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 09:39:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ejpt #webshell
Medium
eJPT Lab Write-Up: Host & Network Penetration Testing: Exploitation CTF 3
This write-up covers the Host & Network Penetration Testing: Exploitation CTF 3from the INE Penetration Testing Student course, preparing…
⤷ Title: Detecting Web Shells Walkthrough. TryHackMe
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:32:03 GMT
════════════════════════
⌗ Tags: #webshell #cybersecurity #tryhackme_walkthrough #log_analysis
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:32:03 GMT
════════════════════════
⌗ Tags: #webshell #cybersecurity #tryhackme_walkthrough #log_analysis
Medium
Detecting Web Shells Walkthrough. TryHackMe
Hey Everyone,
⤷ Title: HTB SQL INJECTION FUNDAMENTALS 2025 [UPDATED SKILLS ASSESSMENT]
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 20:58:08 GMT
════════════════════════
⌗ Tags: #webshell #hackthebox_writeup #sql_injection #hackthebox #database
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 20:58:08 GMT
════════════════════════
⌗ Tags: #webshell #hackthebox_writeup #sql_injection #hackthebox #database
Medium
HTB SQL INJECTION FUNDAMENTALS 2025 [UPDATED SKILLS ASSESSMENT]
SQL injection is one of the most fundamental vulnerabilities in web applications, and mastering it is essential for anyone starting out in…
⤷ Title: Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
Daily CyberSecurity
Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
A college student is selling access to 5,200+ gov/edu sites via the undetectable Beima PHP Webshell. The custom backdoor allows full RCE and fuels a growing cybercrime freelancing marketplace.
⤷ Title: CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Networks #CISA KEV #Command Injection #CVE_2025_66644 #D_Link #EOL #Japan #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Networks #CISA KEV #Command Injection #CVE_2025_66644 #D_Link #EOL #Japan #webshell
Daily CyberSecurity
CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
CISA KEV adds EOL D-Link and Array Networks flaws. ArrayOS AG (CVE-2025-66644) is actively exploited in Japan to drop PHP webshells. Retire EOL D-Link and patch ArrayOS AG immediately.
⤷ Title: Tryhackme Writeup: Detecting Web Shell
════════════════════════
𐀪 Author: Sampana
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 11:03:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell
════════════════════════
𐀪 Author: Sampana
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 11:03:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell
Medium
Tryhackme Writeup: Detecting Web Shell
Explore web shell detection by analyzing logs, file systems, and network traffic.
⤷ Title: SQL Injection Vulnerability
════════════════════════
𐀪 Author: t4nu1
════════════════════════
ⴵ Time: Sun, 03 May 2026 06:17:38 GMT
════════════════════════
⌗ Tags: #sql_injection #file_upload #webshell
════════════════════════
𐀪 Author: t4nu1
════════════════════════
ⴵ Time: Sun, 03 May 2026 06:17:38 GMT
════════════════════════
⌗ Tags: #sql_injection #file_upload #webshell
Medium
SQL Injection Vulnerability
Bee
⤷ Title: Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 12:20:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #APT34 #cybersecurity #Data Breach #Hunt Intelligence #infosec #Iran APT #Middle East Security #MuddyWater #OilRig #Oman MJLA #UAE VPS #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 12:20:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #APT34 #cybersecurity #Data Breach #Hunt Intelligence #infosec #Iran APT #Middle East Security #MuddyWater #OilRig #Oman MJLA #UAE VPS #webshell
Daily CyberSecurity
Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
Hunt Intelligence uncovers a massive Iranian-nexus breach targeting the Omani Ministry of Justice. 26k records leaked via an unprotected UAE staging server.
⤷ Title: Massive FreePBX Exploitation Campaign Deploys JOMANGY Webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 08:15:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Cyber Security #Cyble #FreePBX #INJ3CTOR3 #JOMANGY #VoIP Toll Fraud #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 08:15:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Cyber Security #Cyble #FreePBX #INJ3CTOR3 #JOMANGY #VoIP Toll Fraud #webshell
Daily CyberSecurity
Massive FreePBX Exploitation Campaign Deploys JOMANGY Webshell
Cyble researchers uncover a widespread FreePBX exploitation campaign by INJ3CTOR3 deploying the novel JOMANGY webshell for toll fraud.
⤷ Title: Shell Payload Generation & Delivery | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 09:17:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell #pentesting #metasploit
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 09:17:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell #pentesting #metasploit
Medium
Shell Payload Generation & Delivery | TryHackMe
Generate, customise, and deploy shell payloads with msfvenom, Metasploit, and webshells
⤷ Title: CMS Exploitation Campaign Plants Webshells on Business Websites
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CMS Exploitation #CMS Vulnerabilities #Web Security #webshell #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CMS Exploitation #CMS Vulnerabilities #Web Security #webshell #wordpress
Daily CyberSecurity
CMS Exploitation Campaign Plants Webshells on Business Websites
At a glance Actor / group Unattributed malicious cyber actors Activity Mass exploitation of CMS flaws to deploy webshells Targets / victims WordPress and other CMS sites; many Australian SMBs Scal…
⤷ Title: wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 01:49:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60137 #CVE_2026_63030 #Pre_Auth RCE #REST API batch #webshell #WordPress Core RCE #wordpress security #wp2shell exploit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 01:49:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60137 #CVE_2026_63030 #Pre_Auth RCE #REST API batch #webshell #WordPress Core RCE #wordpress security #wp2shell exploit
Daily CyberSecurity
wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
Attackers are already dropping webshells on WordPress sites through a flaw in WordPress Core itself. The bug chain, named wp2shell, delivers an unauthenticated WordPress Core RCE. No plugin, no th…
⤷ Title: Practicing Classic Web Shell Exploitation (HTB Writeup)
════════════════════════
𐀪 Author: Emircan Altuntaş
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 19:15:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #webshell #hackthebox
════════════════════════
𐀪 Author: Emircan Altuntaş
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 19:15:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #webshell #hackthebox
Medium
Practicing Classic Web Shell Exploitation (HTB Writeup)
Recently, I felt like flexing some web exploitation skills and decided to warm up with a classic: uploading a web shell, getting code…