• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

What are WebShell, Get root and Local attack?

AnonyViet by AnonyViet
February 1, 2023
in Security
0

Currently, there are many websites that have been attacked by hackers, hackers can change all files on the system by exploiting vulnerabilities that exist on websites and uploading backdoors and webshells to gain control. these websites altogether. Today I would like to present some issues related to webshell, get root and local attack.

shellcodeb

Join the channel Telegram of the AnonyViet 👉 Link 👈

WebShell terminology: WebShell is a form of malicious code, a backdoor with many functions to support hackers to take control of website systems. WebShell is usually written in many languages ​​and is often the language that the website is using. The basic function is to upload files to the server, connect to the database, bypass the security mechanisms, configure, bruteforce attack, Get Root, Local Attack… as long as the hacker can download the files. If you put this webshell on the website’s system, it is considered that the hacker has full control over that website, even if you don’t know what the account and password of this server is.

WebShell has many different types and variations, not just one file, but they are also modified by hackers into many types to easily upload engraved files to the victim’s server.

logo

Local Atack: This type of hacking is quite common nowadays on the internet. Local attack is a method to attack from one user to another on the same server quickly without any permission.

A server can have 1 or more websites developed on it, then each such website will be granted a user containing all rights to that website. An example is /user/username1. Similarly, there is also a directory /user/username2,/user/username3/, /user/username4…

Assuming /user/username2 is occupied by a hacker, with normal scripts, the hacker can access your files at /user/username1. Attacks based on scripts in one user that attack another user’s host on the same server are called local attacks.

Get Root: Also hijacking a website like Local attack but it is more sophisticated, not taking over each user like Local, but Get Root will take root of the server (root is the highest right in a Unix/Linux server). When the hacker has root privileges of the device, it means that the hacker can manage all websites on this server.

images

How to prevent Local Attack

The following measures will help you prevent hackers from using the local attack method

  • Do not use unknown source code that is shared on the internet uncensored.
  • Regularly update information about patches and vulnerabilities in the source code platform, services, and operating systems that you are using to update vendor patches.
  • CHMOD logical files and folders.
  • Disable functions that interact directly with the terminal (can execute shells directly into the operating system kernel) such as: exec, system, popen….
  • Limit the use of shared hosting with unknown host.
  • Encrypt SQL database tables containing passwords and users, set passwords containing special characters, including numbers, letters and special characters to avoid Bruteforce.
  • Use virus scanners to scan the entire source code before using it and you should do this periodically to prevent hackers from inserting backdoors and malicious scripts on the server.

We hope this analysis can help you better secure your systems.

The article achieved: 5/5 – (100 votes)

Tags: AttackLocalrootWebShell
Previous Post

How to use App 1.1.1.1 on a computer to access blocked websites

Next Post

How to add and export saved passwords on Chrome browser

AnonyViet

AnonyViet

Related Posts

How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Seekr: Collect & manage OSINT data
Security

Seekr: Collect & manage OSINT data

November 22, 2024
Next Post
How to add and export saved passwords on Chrome browser

How to add and export saved passwords on Chrome browser

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Top 5 game programming languages ​​to learn now

Top 5 game programming languages ​​to learn now

June 8, 2025
The iPhone list is updated with iOS 26

The iPhone list is updated with iOS 26

June 8, 2025
Discover the glowing effect next to the iPhone ios 18 screen

Discover the glowing effect next to the iPhone ios 18 screen

June 8, 2025
[Godot Shooter] #2: Creating characters & shooting bullets

[Godot Shooter] #2: Creating characters & shooting bullets

June 7, 2025
Top 5 game programming languages ​​to learn now

Top 5 game programming languages ​​to learn now

June 8, 2025
The iPhone list is updated with iOS 26

The iPhone list is updated with iOS 26

June 8, 2025
Discover the glowing effect next to the iPhone ios 18 screen

Discover the glowing effect next to the iPhone ios 18 screen

June 8, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Top 5 game programming languages ​​to learn now

Top 5 game programming languages ​​to learn now

June 8, 2025
The iPhone list is updated with iOS 26

The iPhone list is updated with iOS 26

June 8, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET https://kubet88.yoga/ bj88

No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET https://kubet88.yoga/ bj88

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply