Attack (Attack ID:302019)

Release Date03/20/2012

Attack NameDetected WebShell PHPSpy 200X

Severity

BUG ID

CVE ID

 

Description

PHPSpy2008 WebShell is a web-based Trojan running in PHP environment which is designed to compromise Web servers without being noticed. It can breach firewalls and monitor Web servers through Internet remotely. The main functions include:
File management, host information reconnaissance, web proxy, remote command and script execution, database operation, webpage trojaning, privilege escalation, etc.

Affected system:
Windows and Unix Web servers
PHPSpy 2006
PHPSpy 2008
YuanFen PHP Shell

 

Solution

Delete the PHP Trojan webpage and fix the vulnerability.