What is a web shell?¶
A web shell is code placed in a web-accessible environment so that requests to the server can trigger commands or other unauthorised actions. It can provide remote access long after the vulnerability or stolen credential used to place it has been addressed.
The shell may be a small standalone script, altered application code or functionality hidden among legitimate site files. It can browse directories, transfer files, run commands, change content or support movement into other systems.
Connect the file, request and process¶
Preserve the suspected code, full path, hashes and filesystem metadata before removal. Examine its capabilities, but prove use through the surrounding server evidence.
Web and application logs may show requests to the shell. Process telemetry may show the web-server process starting a command interpreter or utility. File changes and outbound connections may show the result. Linking those sources is stronger than relying on an unusual filename or URL alone.
A request does not always mean a command executed successfully: it may be a scan, failed authentication or an error. Conversely, missing requests do not exclude use where logs are incomplete, deleted or held on another component.
Establish how it arrived¶
Possible routes include exploitation of a public-facing application, stolen administrative credentials, a vulnerable upload feature, file transfer or a compromised developer account. Deployment and authentication logs, code-repository history and vulnerability evidence can help distinguish them.
Ordinary web requests may carry the control traffic, so unusual appearance is not required. Look for the functional relationship between request parameters, child processes and changes on the server. A confirmed shell establishes a mechanism; its creator and controller still require account, infrastructure and access evidence.
Key takeaway
A web shell is a remote command mechanism: preserve its code, prove use by linking requests to server-side effects, and investigate its placement route separately.