Diamond Member ThaHaka 0 Posted April 3 Diamond Member Share Posted April 3 This is the hidden content, please Sign In or Sign Up Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the This is the hidden content, please Sign In or Sign Up Defender Security Research Team. "Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution, This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/307652-h4ckn3wsmicrosoft-details-cookie-controlled-php-web-shells-persisting-via-cron-on-linux-servers/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.