本文へ移動
cccskills
無料GitHub で公開

security-webshells

Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.

インストール方法を見る

含まれるファイル(62)

  • SKILL.md2.5 KB
  • references/Web-Shells/backdoor_list.txt14.4 KB
  • references/Web-Shells/CFM/shell.cfm.html2.4 KB
  • references/Web-Shells/FuzzDB/cmd-simple.php328 B
  • references/Web-Shells/FuzzDB/cmd.aspx1.4 KB
  • references/Web-Shells/FuzzDB/cmd.jsp829 B
  • references/Web-Shells/FuzzDB/cmd.php320 B
  • references/Web-Shells/FuzzDB/cmd.sh8.2 KB
  • references/Web-Shells/FuzzDB/list.jsp1.8 KB
  • references/Web-Shells/FuzzDB/list.php557 B
  • references/Web-Shells/FuzzDB/list.sh817 B
  • references/Web-Shells/FuzzDB/nc.exe27.5 KB
  • references/Web-Shells/FuzzDB/reverse.jsp2.4 KB
  • references/Web-Shells/FuzzDB/up.php663 B
  • references/Web-Shells/FuzzDB/up.sh764 B
  • references/Web-Shells/JSP/simple-shell.jsp63 B
  • references/Web-Shells/laudanum-1.0/asp/dns.asp4.3 KB
  • references/Web-Shells/laudanum-1.0/asp/file.asp5.6 KB
  • references/Web-Shells/laudanum-1.0/asp/proxy.asp12.6 KB
  • references/Web-Shells/laudanum-1.0/asp/shell.asp3.2 KB
  • references/Web-Shells/laudanum-1.0/aspx/shell.aspx4.2 KB
  • references/Web-Shells/laudanum-1.0/cfm/shell.cfm4.2 KB
  • references/Web-Shells/laudanum-1.0/CREDITS305 B
  • references/Web-Shells/laudanum-1.0/GPL14.6 KB
  • references/Web-Shells/laudanum-1.0/jsp/cmd.war1.2 KB
  • references/Web-Shells/laudanum-1.0/jsp/makewar.sh39 B
  • references/Web-Shells/laudanum-1.0/jsp/warfiles/cmd.jsp1.1 KB
  • references/Web-Shells/laudanum-1.0/jsp/warfiles/META-INF/MANIFEST.MF68 B
  • references/Web-Shells/laudanum-1.0/jsp/warfiles/WEB-INF/web.xml341 B
  • references/Web-Shells/laudanum-1.0/php/dns.php5.0 KB
  • references/Web-Shells/laudanum-1.0/php/file.php6.1 KB
  • references/Web-Shells/laudanum-1.0/php/host.php4.3 KB
  • references/Web-Shells/laudanum-1.0/php/killnc.php3.8 KB
  • references/Web-Shells/laudanum-1.0/php/php-reverse-shell.php5.4 KB
  • references/Web-Shells/laudanum-1.0/php/proxy.php11.1 KB
  • references/Web-Shells/laudanum-1.0/php/shell.php13.3 KB
  • references/Web-Shells/laudanum-1.0/README1.6 KB
  • references/Web-Shells/laudanum-1.0/wordpress/laudanum.php3.2 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/dns.php4.5 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/file.php5.7 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/host.php3.9 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/ipcheck.php2.2 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/killnc.php3.4 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/php-reverse-shell.php5.5 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/proxy.php10.7 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/settings.php2.7 KB
  • references/Web-Shells/laudanum-1.0/wordpress/templates/shell.php12.5 KB
  • references/Web-Shells/Magento/newadmin-Inchoo.php2.0 KB
  • references/Web-Shells/Magento/newadmin-KINKCreative.php1.4 KB
  • references/Web-Shells/PHP/another-obfuscated-phpshell.php712 B
  • references/Web-Shells/PHP/Dysco.php1.3 KB
  • references/Web-Shells/PHP/obfuscated-phpshell.php255 B
  • references/Web-Shells/Vtiger/languages/en_us/Settings/VtigerVulnPlugin.php19 B
  • references/Web-Shells/Vtiger/languages/en_us/VtigerVulnPlugin.php19 B
  • references/Web-Shells/Vtiger/manifest.xml522 B
  • references/Web-Shells/Vtiger/modules/VtigerVulnPlugin/actions/Gateway.php952 B
  • references/Web-Shells/Vtiger/modules/VtigerVulnPlugin/manifest.xml522 B
  • references/Web-Shells/Vtiger/modules/VtigerVulnPlugin/VtigerVulnPlugin.php972 B
  • references/Web-Shells/Vtiger/README.md402 B
  • references/Web-Shells/Vtiger/settings/actions/Gateway.php869 B
  • references/Web-Shells/WordPress/bypass-login.php634 B
  • references/Web-Shells/WordPress/plugin-shell.php2.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

SecLists Web-Shells

Description

Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.

Source: SecLists/Web-Shells Repository: https://github.com/danielmiessler/SecLists License: MIT

When to Use This Skill

Use this skill when you need:

  • Web shell detection testing
  • Security monitoring validation
  • Malware analysis
  • IDS/IPS signature testing
  • Forensics research

⚠️ IMPORTANT: Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.

Key Files in This Skill

  • PHP shells - Common PHP web shells
  • ASP/ASPX shells - Microsoft web shells
  • JSP shells - Java server pages shells
  • Python shells - Python-based shells
  • Perl shells - Perl web shells

Usage Example

# Access files from this skill
import os

# Example: Load patterns/payloads
skill_path = "references/Web-Shells"

# List all available files
for root, dirs, files in os.walk(skill_path):
    for file in files:
        if file.endswith('.txt'):
            filepath = os.path.join(root, file)
            print(f"Found: {filepath}")
            
            # Read file content
            with open(filepath, 'r', errors='ignore') as f:
                content = f.read().splitlines()
                print(f"  Lines: {len(content)}")

Security & Ethics

Authorized Use Cases ✅

  • Authorized penetration testing with written permission
  • Bug bounty programs (within scope)
  • CTF competitions
  • Security research in controlled environments
  • Testing your own systems
  • Educational demonstrations

Prohibited Use Cases ❌

  • Unauthorized access attempts
  • Testing without permission
  • Malicious activities
  • Privacy violations
  • Any illegal activities

Complete SecLists Collection

This is a curated subset of SecLists. For the complete collection:


Generated by Skill Seeker | SecLists Web-Shells Collection License: MIT - Use responsibly with proper authorization

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Execute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag explicitly enabled. This attack generates a recoverable Ticket Granting Ticket (TGT) without requiring the attacker to authenticate first.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

ShulkwiSEC のスキルをすべて見る

このスキルの問題を報告する