I wrote these shit code just to make a POC of WebshellKiller jump to WebshellKiller and you will see it...
The program runs on Flask
, and may load slowly because the WebshellDetector should load completely before use.
- Firstly, run this program, then you can see as follow:
- Then, we enter the frontpage
- and click the
OfflineDetect
button
- Input a valid directory, click the button and see the result as follow:
- The same way click the
RealtimeDetect
button
- Copy some evil files(extension with php, jsp, aspx...) into monitored directory
- Easy to use, good luck and have fun...