'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Behinder3.0 Webshell Access
Severity:high
CVE ID:
| Descripiton:
|
WebShell is a kind of command execution envrionment which is in the form of Web page files like asp, php, jsp, cgi, etc. WebShell is also known as backdoor of websites because it helps to obtain a certain operation permissions to Web servers. WebShell can not only be used to manage websites and Web servers for administrators, but also be used by invaders to control Web server maliciously. This rule inspects PHP base64 decoding code in HTTP request to find out and prevent WebShell attack attempt. Behinder is a very popular Webshell client, which establishes an encrypted tunnel in the HTTP protocol to avoid detection by security devices. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.