Files
Anthropic-Cybersecurity-Skills/skills/hunting-for-webshells-in-web-servers.bak/references/api-reference.md
T
mukul975 c47eed6a64 Production hardening: security fixes, code quality, 724 skills complete
- Fix 25 shell=True subprocess calls with list-based commands
- Fix 49 verify=False in defensive skills (env-var override)
- Add timeout to 231 HTTP/subprocess/socket calls
- Fix 6 SQL injection patterns with whitelist validation
- Replace 8 __import__() with standard imports
- Remove 701 unused imports across 442 files
- Add authorized-testing disclaimers to all offensive skills
- Complete 11 incomplete skill directories
- Expand 10 stub SKILL.md files with full content
- Fix 2 YAML parse errors in frontmatter
- Fix 5 pre-existing syntax errors
- Convert 22 hardcoded paths/ports to environment variables
- Back up 21 redundant skill pairs to .bak
- Fix 2 global declaration errors
- 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE)
- 0 compile errors across all 724 agent.py files
2026-03-19 13:26:49 +01:00

1.7 KiB

API Reference: Hunting for Webshells in Web Servers

Shannon Entropy Calculation

import math

def shannon_entropy(data: bytes) -> float:
    freq = {}
    for byte in data:
        freq[byte] = freq.get(byte, 0) + 1
    length = len(data)
    return -sum((c/length) * math.log2(c/length) for c in freq.values())

# Thresholds: > 5.5 suspicious, > 6.5 likely obfuscated

Webshell Detection Patterns

Pattern Language Risk
eval() PHP HIGH
base64_decode() PHP HIGH
system() / passthru() PHP CRITICAL
shell_exec() / exec() PHP CRITICAL
$_GET/$_POST + eval PHP CRITICAL
Runtime.getRuntime().exec JSP CRITICAL
Server.CreateObject ASP HIGH

YARA Rule for Webshells

rule webshell_php_generic {
    meta:
        description = "Generic PHP webshell"
    strings:
        $eval = "eval(" ascii nocase
        $b64 = "base64_decode(" ascii nocase
        $system = "system(" ascii nocase
        $input = /\$_(GET|POST|REQUEST)\s*\[/ ascii
    condition:
        $input and ($eval or $b64 or $system)
}

File System Scanning

from pathlib import Path
SCRIPT_EXTS = {".php", ".asp", ".aspx", ".jsp", ".jspx", ".cgi"}
for f in Path("/var/www/html").rglob("*"):
    if f.suffix.lower() in SCRIPT_EXTS:
        entropy = shannon_entropy(f.read_bytes())

NeoPI (Webshell Detection Tool)

python neopi.py /var/www/html -a  # Run all tests
# Tests: entropy, longest word, index of coincidence, signature

References