CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard
A penetration tester has compromised a web application and gained initial access. To maintain persistent access, the tester wants to deploy a web shell without being easily detected by file integrity monitoring (FIM) or anti-malware solutions. Which of the following is the most stealthy approach?
- AUploading a standard `.php` web shell to a publicly accessible directory.
- BInjecting a web shell into an existing, frequently accessed legitimate application file.
- CModifying the `.htaccess` file to redirect specific requests to a newly uploaded web shell.
- DCreating a new, uniquely named web shell file in a hidden directory.
Show answer & explanationAnswer & explanation
Correct answer: B. Injecting a web shell into an existing, frequently accessed legitimate application file.
Injecting a web shell into an existing, frequently accessed legitimate application file is the most stealthy approach. This avoids creating new files that FIM might detect and leverages the trusted status of an existing file. The web shell code can be blended into comments or existing functions, making it harder for signature-based detection and manual review.
Why the other options are wrong
- A. Uploading a new, standard web shell is easily detected by FIM and signature-based antivirus.
- C. Modifying `.htaccess` is a common indicator of compromise and can be easily detected by FIM and security tools.
- D. Creating a new file, even in a hidden directory, can still be detected by FIM solutions.
Web Shell Injection (Deep)
A stealthy web shell deployment technique where malicious code is embedded directly into an existing, legitimate application file on the web server, rather than uploading a new, standalone web shell file.
- Bypasses file integrity monitoring (FIM) that checks for new files.
- Requires careful blending of malicious code with legitimate code to avoid detection.
- Can be harder to detect via signature-based antivirus if obfuscated.
Memory trick: Inject into existing code, hide in plain sight.