🚀Cyber Security Certification Notes & Cheat Sheets
https://buymeacoffee.com/notescatalog...
🚀 Cyber Security Certification Notes (Another Link)
https://shop.motasem-notes.net/collec...
💡 Cyber Security Notes | Membership Access
https://buymeacoffee.com/notescatalog...
💡Web Hacking & Pentesting Study Notes
https://buymeacoffee.com/notescatalog...
💡Offensive Security Web Assessor (OSWA) Study Notes (Unofficial)
https://buymeacoffee.com/notescatalog...
🔥 Download FREE Cyber Security 101 Study Notes
https://buymeacoffee.com/notescatalog...
💡Video Writeup
https://motasem-notes.net/web-shells-...
💡Brand collaborations and sponsorships
https://motasem-notes.net/advertise/
******
Web shells are one of the most common backdoors used by attackers to gain remote access to systems. In this video, we’ll explore what web shells are, how attackers use them, and most importantly , how to detect them using logs, monitoring tools, and SOC workflows.
****
Store
https://buymeacoffee.com/notescatalog...
Patreon
/ motasemhamdan
Instagram
/ motasem.hamdan.official
LinkedIn
[1]: / motasem-hamdan-7673289b
[2]: / motasem-eldad-ha-bb42481b2
Twitter
/ manmotasem
Facebook
/ motasemhamdantty
TikTok
/ motasemhamdan0
****
00:00 - Introduction to Web Shells
00:50 - How Web Shells Are Uploaded
01:36 - Attacker Capabilities with Web Shells
02:34 - Persistence, Recon, Privilege Escalation & Exfiltration
03:29 - MITRE ATT&CK Mapping for Web Shells
04:33 - Common Web Shell File Extensions
04:49 - Examples of Web Shells (One-Liners & Full Shells)
05:22 - PHP One-Liner Web Shells
07:11 - Interacting with Web Shells via URL Parameters
08:12 - Using "whoami" to Check Account Access
08:35 - Finding Flags via ls & cat
08:55 - Detecting Web Shells in Logs
09:11 - Repeated GET Requests as Indicators
09:58 - POST + Multiple GET Requests Pattern
10:23 - Suspicious User-Agent Strings
11:21 - Suspicious Query Strings (cmd, exec, Base64)
12:00 - Example Suspicious Log Entry
12:59 - Auditd Syscall "create" for Detection
13:23 - File Paths to Inspect (Apache, Nginx, Temp, CMS)
14:04 - WordPress Web Shell Injection in Theme Files
14:25 - Using `find` Command to Locate PHP Web Shells
15:49 - Reviewing Results with Less
16:09 - Packet Capture Analysis with Wireshark
16:54 - Detecting Web Shell via HTTP Requests
18:05 - Wireshark Filter for PUT Requests
18:32 - Investigative Scenario: Compromised WordPress Site
19:12 - Access Log Analysis with grep
20:48 - Detecting Reconnaissance via 404 Responses
21:36 - Identifying Attacker IP
22:08 - Valid 200 Responses Confirming Discovery
23:27 - Identifying Uploaded Web Shell via POST Request
24:41 - First Command Executed (whoami)
25:31 - Attacker’s Second File Upload (LinPEAS)
26:52 - Hidden Secret in Web Shell (Flag Extraction)
27:35 - Conclusion & Wrap-Up