r57shell Backdoor Detection

high Nessus Plugin ID 46350

Synopsis

The remote web server contains a PHP backdoor script.

Description

At least one instance of r57shell is hosted on the remote web server. This is a PHP script that acts as a backdoor and provides a convenient set of tools for attacking the affected host.

Solution

Remove any instances of the script and conduct a forensic examination to determine how it was installed as well as whether other unauthorized changes were made.

Plugin Details

Severity: High

ID: 46350

File Name: r57shell.nasl

Version: 1.5

Type: remote

Family: CGI abuses

Published: 5/14/2010

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Required KB Items: www/PHP

Excluded KB Items: Settings/disable_cgi_scanning