Skip to main navigation Skip to search Skip to main content

No honor among thieves: A large-scale analysis of malicious web shells

  • Oleksii Starov
  • , Johannes Dahse
  • , Syed Sharique Ahmad
  • , Thorsten Holz
  • , Nick Nikiforakis
  • Stony Brook University
  • Ruhr University Bochum

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

49 Scopus citations

Abstract

Web shells are malicious scripts that attackers upload to a compromised web server in order to remotely execute arbi-trary commands, maintain their access, and elevate their privileges. Despite their high prevalence in practice and heavy involvement in security breaches, web shells have never been the direct subject of any study. In contrast, web shells have been treated as malicious blackboxes that need to be detected and removed, rather than malicious pieces of soft-ware that need to be analyzed and, in detail, understood. In this paper, we report on the first comprehensive study of web shells. By utilizing different static and dynamic anal-ysis methods, we discover and quantify the visible and in-visible features offered by popular malicious shells, and we discuss how attackers can take advantage of these features. For visible features, we find the presence of password brute-forcers, SQL database clients, portscanners, and checks for the presence of security software installed on the compro-mised server. In terms of invisible features, we find that about half of the analyzed shells contain an authentication mechanism, but this mechanism can be bypassed in a third of the cases. Furthermore, we find that about a third of the analyzed shells perform homephoning, i.e., the shells, upon execution, surreptitiously communicate to various third par-ties with the intent of revealing the location of new shell in-stallations. By setting up honeypots, we quantify the num-ber of third-party attackers benefiting from shell installa-tions and show how an attacker, by merely registering the appropriate domains, can completely take over all installa-tions of specific vulnerable shells.

Original languageEnglish
Title of host publication25th International World Wide Web Conference, WWW 2016
PublisherInternational World Wide Web Conferences Steering Committee
Pages1021-1032
Number of pages12
ISBN (Electronic)9781450341431
DOIs
StatePublished - 2016
Event25th International World Wide Web Conference, WWW 2016 - Montreal, Canada
Duration: Apr 11 2016Apr 15 2016

Publication series

Name25th International World Wide Web Conference, WWW 2016

Conference

Conference25th International World Wide Web Conference, WWW 2016
Country/TerritoryCanada
CityMontreal
Period04/11/1604/15/16

Fingerprint

Dive into the research topics of 'No honor among thieves: A large-scale analysis of malicious web shells'. Together they form a unique fingerprint.

Cite this