Webshell
Uploading a Web Shell
Once we have our web shell, we need to place our web shell script into the remote host's web directory (webroot) to execute the script through the web browser. This can be through a vulnerability in an upload feature, which would allow us to write one of our shells to a file, i.e. shell.php
and upload it, and then access our uploaded file to execute commands.
However, if we only have remote command execution through an exploit, we can write our shell directly to the webroot to access it over the web. So, the first step is to identify where the webroot is. The following are the default webroots for common web servers:
Web Server | Default Webroot |
---|---|
| /var/www/html/ |
| /usr/local/nginx/html/ |
| c:\inetpub\wwwroot\ |
| C:\xampp\htdocs\ |
Last updated