Webshell Backdoors: How They Enter, What Attackers Can Do, and How to Fix Website Weak Points
A website can look normal while an attacker secretly accesses its files. One way this happens is through a webshell backdoor.
A webshell is malicious server-side code, often stored in a PHP file. An attacker sends requests to that file to browse folders, read files, upload more malware, or run commands.
Its access depends on the permissions of the user running PHP.
How Does a Webshell Backdoor Get Installed?
An attacker first needs a way to place or modify executable code on the server.
| Possible entry point | Simple explanation |
|---|---|
| Vulnerable plugin or theme | A software bug allows unauthorized file uploads or code execution. |
| Stolen administrator account | An attacker uses dashboard permissions to install malicious code. |
| Unsafe upload feature | An upload endpoint accepts executable files that it should reject. |
| Stolen hosting or deployment credentials | An attacker directly changes website files. |
| Writable website code | Existing malicious code can modify files and create additional backdoors. |
These are possible causes. Finding an old plugin does not prove that attackers used it.
In the incident examined here, webshells were reported inside WordPress websites. The exact weakness used to plant them remains unknown.
When Does the Backdoor Become Accessible?
A backdoor becomes accessible when the malicious file is installed in a location the server can execute and the attacker can reach it.
For example, a malicious PHP file inside a publicly served plugin folder may receive requests through a URL such as:
https://example.com/wp-content/plugins/suspicious.php
This is an illustrative URL. Do not open suspected webshell URLs to test them; inspect files and logs instead.
The incident report describes webshell activity between 7 August and 26 September 2026. That is the reported activity window, not proof of the exact installation date.
A later screenshot also reports a remaining backdoor at:
/opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Its current presence must be checked on the server.
Why Do Attackers Hide Webshells?
Webshells provide remote access without requiring a normal SSH login.
Attackers may give them ordinary-looking names, place them among legitimate PHP files, or obscure their contents. In this incident, reported filenames included:
Ge.php
blue.php
Server.php
chengse.php
v.php
A filename alone is not proof of malware. The file’s contents and surrounding evidence must be reviewed.
What Can an Attacker Do Through a Webshell?
| Action | Required access | Possible impact |
|---|---|---|
| Browse directories | Directory access | Discover other websites and applications. |
| Read files | Read permission | Expose SMTP passwords, database credentials, and API secrets. |
| Modify files | Write permission | Replace homepages, inject redirects, or change application behavior. |
| Upload files | Writable directories | Install additional backdoors. |
| Execute commands | Available execution capability | Perform actions as the PHP user. |
| Access databases | Valid credentials and network access | Read or modify data within the database account’s permissions. |
| Send emails | Valid SMTP credentials | Send spam or phishing messages. |
A webshell does not automatically provide root access. However, ordinary web-user permissions can still expose significant data.
How One Website Can Affect Other Files and Applications
In the reported incident, the webshell ran as the daemon user.
That user could access other application folders and read .env files containing secrets.
The reported exposure route was:
WordPress webshell → daemon permissions → other application folders → readable application secrets.
| Other file or location | Possible effect if accessible |
|---|---|
Laravel .env
|
SMTP, database, and API credentials may be exposed. |
WordPress wp-config.php
|
Database credentials and authentication secrets may be exposed. |
index.php |
Homepage or application entry point may be replaced. |
.htaccess |
Redirects or access rules may be changed. |
| Plugins and themes | Malicious code may be inserted. |
| Backups | Older credentials and data may be exposed. |
| Writable uploads/cache folders | Additional malicious files may be stored. |
The report did not directly prove SMTP password theft. It established that the credentials were readable by the compromised user.
Weak Points Identified in the Report
All paths below use /opt/lampp/htdocs as their base.
| Reported weak point | Location | Required improvement |
|---|---|---|
| Reported remaining backdoor | holidaylandmark/blog/wp-content/plugins/Down.php |
Verify and quarantine the malicious file. |
| Writable WordPress code | sreschool, cloudopsnow, blog, and comments sites | Restrict code modification by the web user. |
| Old WordPress installations |
holidaylandmark/comments-management/ and comments-management1/
|
Perform tested updates. |
| Old plugins | Those sites’ wp-content/plugins/ folders |
Review and update affected plugins. |
| Dashboard file editor enabled | Those sites’ wp-config.php files |
Disable dashboard code editing. |
| Shared PHP execution user | Server configuration | Separate unrelated applications. |
| Readable secrets | Application .env files |
Restrict access and rotate exposed credentials. |
| Old server software | XAMPP Apache/PHP/OpenSSL | Plan a supported, tested upgrade. |
Having many plugins is not automatically a vulnerability. Vulnerable, unnecessary, or untrusted plugins increase the problem.
Commands to Investigate the Backdoor
These checks are read-only unless explicitly marked otherwise. Preserve logs and do not execute suspicious PHP files.
1. Check Whether the Reported Backdoor Exists
sudo stat /opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Purpose: Show file existence, owner, permissions, and timestamps. Timestamps alone do not establish when an attacker installed it.
Record its hash:
sudo sha256sum /opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Purpose: Create an identifier for the file’s current contents.
2. Find Requests to Known Webshell Names
sudo find /opt/lampp/logs -type f -print0 |
sudo xargs -0 -r zgrep -haiE '(blue\.php|Ge\.php|PHPMailer/Server\.php|chengse\.php|youtube/v\.php|/Down\.php)'
Purpose: Display matching requests
Top comments (0)