Web Shell (Backdoor) — What Is It and How Do You Find One?
What is a web shell?
A web shell (also known as a backdoor) is a malicious PHP file (less commonly Python, Perl, or ASP) that, once placed on a server, gives an attacker remote access to the system through a web browser. All they need is the file’s URL and possibly a password — then they can execute arbitrary commands on the server, browse files, edit databases, or send spam.
A web shell is often the first thing a hacker installs after a successful attack — even before infecting WordPress files. This means that even if the website owner updates WordPress and removes visible infections, the attacker can return through the web shell and start all over again.
What does a web shell look like?
Advanced web shells have elaborate graphical interfaces with a file manager, SQL console, network tools, and a code editor. Simpler ones look like a few lines of code:
<?php if(isset($_REQUEST['cmd'])){ echo shell_exec($_REQUEST['cmd']); } ?>
A file like this, placed for example at yourdomain.com/wp-content/uploads/x.php, allows any system command to be executed through a URL: ...x.php?cmd=ls+-la
How do hackers disguise web shells?
Hackers use various concealment techniques:
- Base64 obfuscation — the entire code is encoded and only decoded at runtime:
eval(base64_decode("cGhwaW5mbygpOw=="));
- Hiding in images — a file with a
.php extension starts with JPEG/PNG bytes to make it look like an image
- Empty files with hidden code — code is injected at the end of the file as whitespace after
?>
- Names imitating original files —
wp-includes/class-wp-db.php vs. the malicious wp-includes/class-wp-db_.php
Where are web shells most commonly hidden?
wp-content/uploads/ — the most common location because PHP can write to this folder
wp-content/cache/ — similarly, writable by caching mechanisms
wp-includes/ — hackers inject files that imitate original WordPress files
- Temporary and session directories outside public_html — often overlooked during scans
- Nested folders with random names, e.g.
uploads/2024/03/a7f8e/
How do you find a web shell on a server?
Method 1 — Search for PHP files in directories where they should not be
find wp-content/uploads -name "*.php" -o -name "*.php5" -o -name "*.phtml"
Method 2 — Search for characteristic functions
grep -r "shell_exec|system(|exec(|passthru|base64_decode" --include="*.php" -l public_html/
Method 3 — Files with a recent modification date
find public_html -name "*.php" -mtime -30 -ls | sort -k8
This will show all PHP files modified in the last 30 days. Any file you do not recognize requires attention.
I found a web shell — what now?
Do not delete it right away. First:
- Record the file’s modification date and permissions
- Check the server logs for requests to this file — this will tell you when it was used and from which IP addresses
- Search nearby directories — web shells are usually not alone; there may be more in the same location
- Only then delete the file and check whether the infection has returned after 24 hours
If you do not have access to server logs or do not know how to interpret them — contact us. Log analysis is a key part of every professional malware cleanup.