Debug School

rakesh kumar
rakesh kumar

Posted on

Webshell Backdoors: How They Enter, What Attackers Can Do, and How to Fix Website Weak Points

Webshell Backdoors: How They Enter, What Attackers Can Do, and How to Fix Website Weak Points

A website can look normal while an attacker secretly accesses its files. One way this happens is through a webshell backdoor.

A webshell is malicious server-side code, often stored in a PHP file. An attacker sends requests to that file to browse folders, read files, upload more malware, or run commands.

Its access depends on the permissions of the user running PHP.

How Does a Webshell Backdoor Get Installed?

An attacker first needs a way to place or modify executable code on the server.

Possible entry point Simple explanation
Vulnerable plugin or theme A software bug allows unauthorized file uploads or code execution.
Stolen administrator account An attacker uses dashboard permissions to install malicious code.
Unsafe upload feature An upload endpoint accepts executable files that it should reject.
Stolen hosting or deployment credentials An attacker directly changes website files.
Writable website code Existing malicious code can modify files and create additional backdoors.

These are possible causes. Finding an old plugin does not prove that attackers used it.

In the incident examined here, webshells were reported inside WordPress websites. The exact weakness used to plant them remains unknown.

When Does the Backdoor Become Accessible?

A backdoor becomes accessible when the malicious file is installed in a location the server can execute and the attacker can reach it.

For example, a malicious PHP file inside a publicly served plugin folder may receive requests through a URL such as:

https://example.com/wp-content/plugins/suspicious.php
Enter fullscreen mode Exit fullscreen mode

This is an illustrative URL. Do not open suspected webshell URLs to test them; inspect files and logs instead.

The incident report describes webshell activity between 7 August and 26 September 2026. That is the reported activity window, not proof of the exact installation date.

A later screenshot also reports a remaining backdoor at:

/opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Enter fullscreen mode Exit fullscreen mode

Its current presence must be checked on the server.

Why Do Attackers Hide Webshells?

Webshells provide remote access without requiring a normal SSH login.

Attackers may give them ordinary-looking names, place them among legitimate PHP files, or obscure their contents. In this incident, reported filenames included:

Ge.php
blue.php
Server.php
chengse.php
v.php
Enter fullscreen mode Exit fullscreen mode

A filename alone is not proof of malware. The file’s contents and surrounding evidence must be reviewed.

What Can an Attacker Do Through a Webshell?

Action Required access Possible impact
Browse directories Directory access Discover other websites and applications.
Read files Read permission Expose SMTP passwords, database credentials, and API secrets.
Modify files Write permission Replace homepages, inject redirects, or change application behavior.
Upload files Writable directories Install additional backdoors.
Execute commands Available execution capability Perform actions as the PHP user.
Access databases Valid credentials and network access Read or modify data within the database account’s permissions.
Send emails Valid SMTP credentials Send spam or phishing messages.

A webshell does not automatically provide root access. However, ordinary web-user permissions can still expose significant data.

How One Website Can Affect Other Files and Applications

In the reported incident, the webshell ran as the daemon user.

That user could access other application folders and read .env files containing secrets.

The reported exposure route was:

WordPress webshell → daemon permissions → other application folders → readable application secrets.

Other file or location Possible effect if accessible
Laravel .env SMTP, database, and API credentials may be exposed.
WordPress wp-config.php Database credentials and authentication secrets may be exposed.
index.php Homepage or application entry point may be replaced.
.htaccess Redirects or access rules may be changed.
Plugins and themes Malicious code may be inserted.
Backups Older credentials and data may be exposed.
Writable uploads/cache folders Additional malicious files may be stored.

The report did not directly prove SMTP password theft. It established that the credentials were readable by the compromised user.

Weak Points Identified in the Report

All paths below use /opt/lampp/htdocs as their base.

Reported weak point Location Required improvement
Reported remaining backdoor holidaylandmark/blog/wp-content/plugins/Down.php Verify and quarantine the malicious file.
Writable WordPress code sreschool, cloudopsnow, blog, and comments sites Restrict code modification by the web user.
Old WordPress installations holidaylandmark/comments-management/ and comments-management1/ Perform tested updates.
Old plugins Those sites’ wp-content/plugins/ folders Review and update affected plugins.
Dashboard file editor enabled Those sites’ wp-config.php files Disable dashboard code editing.
Shared PHP execution user Server configuration Separate unrelated applications.
Readable secrets Application .env files Restrict access and rotate exposed credentials.
Old server software XAMPP Apache/PHP/OpenSSL Plan a supported, tested upgrade.

Having many plugins is not automatically a vulnerability. Vulnerable, unnecessary, or untrusted plugins increase the problem.

Commands to Investigate the Backdoor

These checks are read-only unless explicitly marked otherwise. Preserve logs and do not execute suspicious PHP files.

1. Check Whether the Reported Backdoor Exists

sudo stat /opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Enter fullscreen mode Exit fullscreen mode

Purpose: Show file existence, owner, permissions, and timestamps. Timestamps alone do not establish when an attacker installed it.

Record its hash:

sudo sha256sum /opt/lampp/htdocs/holidaylandmark/blog/wp-content/plugins/Down.php
Enter fullscreen mode Exit fullscreen mode

Purpose: Create an identifier for the file’s current contents.

2. Find Requests to Known Webshell Names

sudo find /opt/lampp/logs -type f -print0 |
sudo xargs -0 -r zgrep -haiE '(blue\.php|Ge\.php|PHPMailer/Server\.php|chengse\.php|youtube/v\.php|/Down\.php)'
Enter fullscreen mode Exit fullscreen mode

Purpose: Display matching requests

Top comments (0)