Files
Anthropic-Cybersecurity-Skills/skills/hunting-for-webshells-in-web-servers.bak/references/api-reference.md
T
mukul975 c47eed6a64 Production hardening: security fixes, code quality, 724 skills complete
- Fix 25 shell=True subprocess calls with list-based commands
- Fix 49 verify=False in defensive skills (env-var override)
- Add timeout to 231 HTTP/subprocess/socket calls
- Fix 6 SQL injection patterns with whitelist validation
- Replace 8 __import__() with standard imports
- Remove 701 unused imports across 442 files
- Add authorized-testing disclaimers to all offensive skills
- Complete 11 incomplete skill directories
- Expand 10 stub SKILL.md files with full content
- Fix 2 YAML parse errors in frontmatter
- Fix 5 pre-existing syntax errors
- Convert 22 hardcoded paths/ports to environment variables
- Back up 21 redundant skill pairs to .bak
- Fix 2 global declaration errors
- 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE)
- 0 compile errors across all 724 agent.py files
2026-03-19 13:26:49 +01:00

68 lines
1.7 KiB
Markdown

# API Reference: Hunting for Webshells in Web Servers
## Shannon Entropy Calculation
```python
import math
def shannon_entropy(data: bytes) -> float:
freq = {}
for byte in data:
freq[byte] = freq.get(byte, 0) + 1
length = len(data)
return -sum((c/length) * math.log2(c/length) for c in freq.values())
# Thresholds: > 5.5 suspicious, > 6.5 likely obfuscated
```
## Webshell Detection Patterns
| Pattern | Language | Risk |
|---------|----------|------|
| `eval()` | PHP | HIGH |
| `base64_decode()` | PHP | HIGH |
| `system()` / `passthru()` | PHP | CRITICAL |
| `shell_exec()` / `exec()` | PHP | CRITICAL |
| `$_GET/$_POST` + `eval` | PHP | CRITICAL |
| `Runtime.getRuntime().exec` | JSP | CRITICAL |
| `Server.CreateObject` | ASP | HIGH |
## YARA Rule for Webshells
```yara
rule webshell_php_generic {
meta:
description = "Generic PHP webshell"
strings:
$eval = "eval(" ascii nocase
$b64 = "base64_decode(" ascii nocase
$system = "system(" ascii nocase
$input = /\$_(GET|POST|REQUEST)\s*\[/ ascii
condition:
$input and ($eval or $b64 or $system)
}
```
## File System Scanning
```python
from pathlib import Path
SCRIPT_EXTS = {".php", ".asp", ".aspx", ".jsp", ".jspx", ".cgi"}
for f in Path("/var/www/html").rglob("*"):
if f.suffix.lower() in SCRIPT_EXTS:
entropy = shannon_entropy(f.read_bytes())
```
## NeoPI (Webshell Detection Tool)
```bash
python neopi.py /var/www/html -a # Run all tests
# Tests: entropy, longest word, index of coincidence, signature
```
### References
- MITRE T1505.003: https://attack.mitre.org/techniques/T1505/003/
- NeoPI: https://github.com/Neohapsis/NeoPI
- YARA: https://yara.readthedocs.io/