Unraveling an obfuscated PHP web shell! Exploring web shells for malware anlaysis!

  Рет қаралды 1,299

Dr Josh Stroschein - The Cyber Yeti

Dr Josh Stroschein - The Cyber Yeti

6 ай бұрын

Web shells are often used to maintain access to a compromised web server. In this video, we'll explore another popular web shell called ORVX Shell v3. Our focus won't be so much on capabilities, but rather on deobfuscating the many layers of it's source code!
Cybersecurity, reverse engineering, malware analysis and ethical hacking content!
🎓 Courses on Pluralsight 👉🏻 www.pluralsight.com/authors/j...
🌶️ KZbin 👉🏻 Like, Comment & Subscribe!
🙏🏻 Support my work 👉🏻 / joshstroschein
🌎 Follow me 👉🏻 / jstrosch , / joshstroschein
⚙️ Tinker with me on Github 👉🏻 github.com/jstrosch
0:39 ORVX shell capabilities
2:03 Layer 1 of the obfuscation
3:04 Viewing the stages of the PHP code
3:30 Identifying EVALs, breaking up the code
3:45 Cyberchef to the rescue
4:23 Identifying the primary structure of the obfuscation
5:10 More EVALs, more obfuscation
5:44 Finding layer 2
8:48 Changes to the obfuscation
10:30 Devising a strategy
12:00 unPHP

Пікірлер: 8
@ghazialkofahi6653
@ghazialkofahi6653 5 ай бұрын
great video, thank you josh
@jstrosch
@jstrosch 5 ай бұрын
Glad you liked it!
@yurilsaps
@yurilsaps 6 ай бұрын
Amazing job, it’s so sad that blue team Chanel’s are so underrated
@jstrosch
@jstrosch 6 ай бұрын
Thanks for the feedback - if you have any suggestions for promo I’m all ears 🤓
@aiexhibit
@aiexhibit 6 ай бұрын
Thanks Josh, that was a great explainer. I always get tripped up when trying to figure out the indexing locations. This will help me for sure.
@jstrosch
@jstrosch 6 ай бұрын
Great to hear!
@sdfnz
@sdfnz 6 ай бұрын
How does it get "substring" out of "rumbits" (around the 7 minute mark) ? Should it be "runbits" or am I misunderstanding what's going on? Either way, thanks for making this video!
@jstrosch
@jstrosch 6 ай бұрын
Great question! I misspoke a bit, it's "substr" not "substring" - www.php.net/manual/en/function.substr.php. Thanks for pointing that out! That's what I get for getting lazy :)
What is a web shell? Exploring a popular web shells capabilities for malware analysis!
9:40
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 1,8 М.
How-To Install Arkime 4.0 in Linux - A Quick Guide on Installation and Processing PCAPs
11:22
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 2,6 М.
Schoolboy - Часть 2
00:12
⚡️КАН АНДРЕЙ⚡️
Рет қаралды 2,5 МЛН
Gym belt !! 😂😂  @kauermotta
00:10
Tibo InShape
Рет қаралды 18 МЛН
Summer shower by Secret Vlog
00:17
Secret Vlog
Рет қаралды 13 МЛН
Go IS Slower Than PHP | Prime Reacts
5:22
ThePrimeTime
Рет қаралды 76 М.
🔴 Malware Mondays Episode 02 - Investigating Processes with Process Explorer and System Informer
50:01
Explode Malware Safely: Setting Up Your Flare-VM Lab
39:57
SYNACK Time
Рет қаралды 1,4 М.
🔴 Malware Mondays Episode 01 - Identifying Malicious Activity in Process Monitor (ProcMon) Data
55:51
From Word document to Ransomware? Investigate How Template Injection is Used to Execute Macros.
10:35
Dr Josh Stroschein - The Cyber Yeti
Рет қаралды 1,4 М.
explore a Wordpress PHP BACKDOOR webshell
40:09
John Hammond
Рет қаралды 124 М.
My 5 Favorite Linux Shell Tricks for SPEEEEEED (and efficiency)
11:06
ноутбуки от 7.900 в тг laptopshoptop
0:14
Ноутбуковая лавка
Рет қаралды 3,5 МЛН
iPhone 15 Pro Max vs IPhone Xs Max  troll face speed test
0:33
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,1 МЛН
Копия iPhone с WildBerries
1:00
Wylsacom
Рет қаралды 8 МЛН
Мой новый мега монитор!🤯
1:00
Корнеич
Рет қаралды 126 М.
iPhone 15 Pro в реальной жизни
24:07
HUDAKOV
Рет қаралды 487 М.