Web Hack List

Collected research

Covert Web Shells in .NET with Read-Only Web Paths

Given a .NET code-execution bug (SharePoint CVE-2020-1147 deserialization) but a non-writable web directory, an attacker can register a VirtualPathProvider ghost web shell that exists only in memory. It serves a web shell even under precompiled apps and FriendlyUrls, avoids writing to disk, and can even replace existing uncompiled .NET pages, evading file-based detection.

Record

Researcher
Soroush Dalili
Published by
MDSec
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .