Jatayu - Stealthy Stand Alone PHP Web Shell
2022-2-23 11:30:0 Author: www.kitploit.com(查看原文) 阅读量:21 收藏

Stealthy Stand Alone PHP Web Shell

FEATURES

  • Http Header Based Authentication.
  • 100% Undetectable.
  • Exec Function Changer.
  • Nothing Fancy

USAGE

GET /test/jatayu.php?fn=1&&cmd=whoami
Host : http://test.com
Authtoken : bb3b1a1f-0447-42a6-955a-88681fb88499

FUNCTIONS

PARAMETER FUNCTION
fn=1 Calls function shell_exec()
fn=2 Calls function system()
cmd=id Executes command

GENERATE AUTHTOKEN

<?php
$r = unpack('v*', fread(fopen('/dev/random', 'r'),16));
$apiKey = sprintf('%04x%04x-%04x-%04x-%04x-%04x%04x%04x',
$r[1], $r[2], $r[3], $r[4] & 0x0fff | 0x4000,
$r[5] & 0x3fff | 0x8000, $r[6], $r[7], $r[8]);
echo $apiKey;
?>

Jatayu - Stealthy Stand Alone PHP Web Shell Jatayu - Stealthy Stand Alone PHP Web Shell Reviewed by Zion3R on 8:30 AM Rating: 5


文章来源: http://www.kitploit.com/2022/02/jatayu-stealthy-stand-alone-php-web.html
如有侵权请联系:admin#unsafe.sh