Thursday, September 14, 2017

[SANS ISC] Another webshell, another backdoor!

I published the following diary on isc.sans.org: “Another webshell, another backdoor!“.

I’m still busy to follow how webshells are evolving… I recently found another backdoor in another webshell called “cor0.id”. The best place to find webshells remind pastebin.com[1]. When I’m testing a webshell, I copy it in a VM located on a “wild Internet” VLAN in my home lab with, amongst other controls, full packet capture enabled. This way, I can spot immediately is the VM is trying to “phone home” to some external hosts. This was the case this time! [Read more]

 

[The post [SANS ISC] Another webshell, another backdoor! has been first published on /dev/random]



from Xavier

No comments:

Post a Comment