Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team.
“Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution,

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

Next Post

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

Related Posts
Total
0
Share