⤷ Title: n0s4n1ty Pico-CTF
════════════════════════
𐀪 Author: Piyawut Buncharoen
════════════════════════
ⴵ Time: Sat, 24 May 2025 12:39:15 GMT
════════════════════════
⌗ Tags: #ctf #webshell #picoctf #cybersecurity #ctf_writeup
════════════════════════
𐀪 Author: Piyawut Buncharoen
════════════════════════
ⴵ Time: Sat, 24 May 2025 12:39:15 GMT
════════════════════════
⌗ Tags: #ctf #webshell #picoctf #cybersecurity #ctf_writeup
Medium
n0s4n1ty Pico-CTF
Once start up target website and it provide us to upload file.
⤷ Title: CVE-2025-23171 & CVE-2025-23172: Versa Director Bugs Open Doors to Webshell Uploads and Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 02:40:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23171 #CVE_2025_23172 #cybersecurity #PoC #privilege escalation #rce #Remote Code Execution #SD_WAN #Software Defined Networking #Versa Director #Vulnerability #Webhook #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 02:40:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23171 #CVE_2025_23172 #cybersecurity #PoC #privilege escalation #rce #Remote Code Execution #SD_WAN #Software Defined Networking #Versa Director #Vulnerability #Webhook #webshell
Daily CyberSecurity
CVE-2025-23171 & CVE-2025-23172: Versa Director Bugs Open Doors to Webshell Uploads and Command Execution
Two flaws in Versa Director SD-WAN allow authenticated RCE via insecure file uploads and privilege escalation via webhook abuse. PoC code is public.
⤷ Title: Evolusi Webshell: Dari c99 Hingga Backdoor Stealth Modern
════════════════════════
𐀪 Author: Alexithema | Sinzoxp
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 12:19:45 GMT
════════════════════════
⌗ Tags: #php_web_shell #webshell #indonesia #cybersecurity
════════════════════════
𐀪 Author: Alexithema | Sinzoxp
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 12:19:45 GMT
════════════════════════
⌗ Tags: #php_web_shell #webshell #indonesia #cybersecurity
Medium
Evolusi Webshell: Dari c99 Hingga Backdoor Stealth Modern
Perkembangan Webshell
⤷ Title: CISA Warns of “ToolShell”: Critical Exploit Chain Hits SharePoint Servers, Bypasses Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cybersecurity #Exploit Chain #rce #Sharepoint #ToolShell #Vulnerability #webshell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cybersecurity #Exploit Chain #rce #Sharepoint #ToolShell #Vulnerability #webshell #zero_day
Daily CyberSecurity
CISA Warns of "ToolShell": Critical Exploit Chain Hits SharePoint Servers, Bypasses Authentication
CISA issues an urgent warning about "ToolShell," a sophisticated exploit chain targeting SharePoint servers with multiple vulnerabilities to install webshells and steal crypto keys.
⤷ Title: TryHackMe | Detecting Web Shells | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 12:41:46 GMT
════════════════════════
⌗ Tags: #shell #tryhackme #tryhackme_writeup #tryhackme_walkthrough #webshell
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 12:41:46 GMT
════════════════════════
⌗ Tags: #shell #tryhackme #tryhackme_writeup #tryhackme_walkthrough #webshell
Medium
TryHackMe | Detecting Web Shells | WriteUp
Explore web shell detection by analyzing logs, file systems, and network traffic
⤷ Title: Day 77: Other shells
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 22:37:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #shell #bind_shell #webshell #penetration_testing
════════════════════════
𐀪 Author: Nile Okomo
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 22:37:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #shell #bind_shell #webshell #penetration_testing
Medium
Day 77: Other shells
Web and bind shells
⤷ Title: SOC — How You Can Detect Web-Shells
════════════════════════
𐀪 Author: Suraj Singh
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 15:24:18 GMT
════════════════════════
⌗ Tags: #webshell #tryhackme_walkthrough #tryhackme
════════════════════════
𐀪 Author: Suraj Singh
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 15:24:18 GMT
════════════════════════
⌗ Tags: #webshell #tryhackme_walkthrough #tryhackme
Medium
SOC — How You Can Detect Web-Shells
A web shell is a malicious program uploaded to a target web server, enabling adversaries to execute commands remotely. It often serves as…
⤷ Title: From XSS to privesc in Wordpresss: Vulnerable plugins and Admin CSRF nonces to create a new Admin
════════════════════════
𐀪 Author: Rogercastefdez
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 13:36:55 GMT
════════════════════════
⌗ Tags: #webshell #xs #wordpress #csrf #cybersecurity
════════════════════════
𐀪 Author: Rogercastefdez
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 13:36:55 GMT
════════════════════════
⌗ Tags: #webshell #xs #wordpress #csrf #cybersecurity
Medium
From XSS to privesc in Wordpresss: Vulnerable plugins and Admin CSRF nonces to create a new Admin
Step 1: The Root Cause — Visitors Plugin Vulnerability
⤷ Title: Web Shells 101: Your First Step into Digital Backdoors (and How Not to Get Pwned!)
════════════════════════
𐀪 Author: Evilfeonix
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 05:42:05 GMT
════════════════════════
⌗ Tags: #webshell #hacking #backdoor
════════════════════════
𐀪 Author: Evilfeonix
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 05:42:05 GMT
════════════════════════
⌗ Tags: #webshell #hacking #backdoor
Medium
Web Shells 101: Your First Step into Digital Backdoors (and How Not to Get Pwned!)
Hello guy, am evilfeonix! The Digital Firebird.
⤷ Title: Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
Daily CyberSecurity
Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
Symantec exposed a Russian-aligned espionage campaign in Ukraine using LotL tactics. Attackers used a Sandworm-linked webshell (Localolive) and abused scheduled tasks to dump credentials and bypass Windows Defender.
⤷ Title: eJPT Lab Write-Up: Host & Network Penetration Testing: Exploitation CTF 3
════════════════════════
𐀪 Author: Ninadkarkhanis
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 09:39:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ejpt #webshell
════════════════════════
𐀪 Author: Ninadkarkhanis
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 09:39:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ejpt #webshell
Medium
eJPT Lab Write-Up: Host & Network Penetration Testing: Exploitation CTF 3
This write-up covers the Host & Network Penetration Testing: Exploitation CTF 3from the INE Penetration Testing Student course, preparing…
⤷ Title: Detecting Web Shells Walkthrough. TryHackMe
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:32:03 GMT
════════════════════════
⌗ Tags: #webshell #cybersecurity #tryhackme_walkthrough #log_analysis
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:32:03 GMT
════════════════════════
⌗ Tags: #webshell #cybersecurity #tryhackme_walkthrough #log_analysis
Medium
Detecting Web Shells Walkthrough. TryHackMe
Hey Everyone,
⤷ Title: HTB SQL INJECTION FUNDAMENTALS 2025 [UPDATED SKILLS ASSESSMENT]
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 20:58:08 GMT
════════════════════════
⌗ Tags: #webshell #hackthebox_writeup #sql_injection #hackthebox #database
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 20:58:08 GMT
════════════════════════
⌗ Tags: #webshell #hackthebox_writeup #sql_injection #hackthebox #database
Medium
HTB SQL INJECTION FUNDAMENTALS 2025 [UPDATED SKILLS ASSESSMENT]
SQL injection is one of the most fundamental vulnerabilities in web applications, and mastering it is essential for anyone starting out in…
⤷ Title: Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
Daily CyberSecurity
Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
A college student is selling access to 5,200+ gov/edu sites via the undetectable Beima PHP Webshell. The custom backdoor allows full RCE and fuels a growing cybercrime freelancing marketplace.
⤷ Title: CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Networks #CISA KEV #Command Injection #CVE_2025_66644 #D_Link #EOL #Japan #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Networks #CISA KEV #Command Injection #CVE_2025_66644 #D_Link #EOL #Japan #webshell
Daily CyberSecurity
CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
CISA KEV adds EOL D-Link and Array Networks flaws. ArrayOS AG (CVE-2025-66644) is actively exploited in Japan to drop PHP webshells. Retire EOL D-Link and patch ArrayOS AG immediately.
⤷ Title: Tryhackme Writeup: Detecting Web Shell
════════════════════════
𐀪 Author: Sampana
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 11:03:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell
════════════════════════
𐀪 Author: Sampana
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 11:03:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #webshell
Medium
Tryhackme Writeup: Detecting Web Shell
Explore web shell detection by analyzing logs, file systems, and network traffic.
⤷ Title: SQL Injection Vulnerability
════════════════════════
𐀪 Author: t4nu1
════════════════════════
ⴵ Time: Sun, 03 May 2026 06:17:38 GMT
════════════════════════
⌗ Tags: #sql_injection #file_upload #webshell
════════════════════════
𐀪 Author: t4nu1
════════════════════════
ⴵ Time: Sun, 03 May 2026 06:17:38 GMT
════════════════════════
⌗ Tags: #sql_injection #file_upload #webshell
Medium
SQL Injection Vulnerability
Bee
⤷ Title: Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 12:20:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #APT34 #cybersecurity #Data Breach #Hunt Intelligence #infosec #Iran APT #Middle East Security #MuddyWater #OilRig #Oman MJLA #UAE VPS #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 12:20:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #APT34 #cybersecurity #Data Breach #Hunt Intelligence #infosec #Iran APT #Middle East Security #MuddyWater #OilRig #Oman MJLA #UAE VPS #webshell
Daily CyberSecurity
Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
Hunt Intelligence uncovers a massive Iranian-nexus breach targeting the Omani Ministry of Justice. 26k records leaked via an unprotected UAE staging server.