CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has compromised a web application and wants to establish a persistent backdoor. The application allows file uploads, but restricts executable formats. The tester successfully uploads a web shell (e.g., 'shell.php'). To ensure persistence even if the web shell is discovered and removed, which technique would be the MOST effective for establishing a secondary, more resilient backdoor?

  1. AEmbedding a backdoor within a commonly used library or framework file of the web application.
  2. BCreating a new administrator user account on the underlying operating system.
  3. CInjecting a malicious payload into a scheduled task on the web server's OS.
  4. DModifying the '.htaccess' file to redirect legitimate requests to a malicious script.
Show answer & explanation

Correct answer: A. Embedding a backdoor within a commonly used library or framework file of the web application.

Embedding a backdoor within a commonly used library or framework file of the web application offers high resilience. These files are less likely to be routinely checked or replaced, and the malicious code can be hidden within legitimate code, making detection difficult even if the primary web shell is removed.

Why the other options are wrong

  • B. Creating a new OS administrator account is a form of persistence, but it's on the OS level, not within the web application itself, and might be detected by system monitoring. It's less 'web application resilient' than embedding code.
  • C. Scheduled tasks are OS-level persistence and can be detected by system administrators or EDR solutions. This is not directly 'within the web application' for resilience.
  • D. Modifying '.htaccess' is often detectable via file integrity monitoring or manual inspection and is easily reversible.

Web Application Backdooring (Deep)

Establishing a resilient backdoor within a web application by modifying core application files, libraries, or framework components to maintain access even if primary web shells are removed.

  • Blends malicious code within legitimate application logic.
  • Difficult to detect without thorough code review or advanced integrity checks.
  • Ensures persistence even after superficial cleanup efforts.

Memory trick: For web app persistence, go deep into the code's core.

More Post-exploitation and Lateral Movement questions