Collected research
Covert Web Shells in .NET with Read-Only Web Paths
Given a .NET code-execution bug (SharePoint CVE-2020-1147 deserialization) but a non-writable web directory, an attacker can register a VirtualPathProvider ghost web shell that exists only in memory. It serves a web shell even under precompiled apps and FriendlyUrls, avoids writing to disk, and can even replace existing uncompiled .NET pages, evading file-based detection.
Record
- Researcher
- Soroush Dalili
- Published by
- MDSec
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .