Post by thedotmaster on Sat Dec 19, 2009 1:04 pm
Anyone can download a backdoor and most can write a backdoor in PHP or whatever, in fact, here are two simple one-liners in PHP:
I'm writing an application that scans for malicious code in web apps (PHP, ASP, etc) and it'd be awesome if people could contribute any little backdoor snippets they can think of.
I've already added code that detects these: ... -backdoor/
and a few other PHP snippets.

All code will be open-sourced when I'm finished.

So then, your backdoors please!
Re: Backdoors in Web Applications

Post by yourmysin on Sat Dec 19, 2009 2:45 pm
Don't forget about popen, passthru and backticks (If PHP is configured for command execution)-

For instance, will display all contents in the directory

`ls -a`;
