PHPsploit Logo

PHPsploit

0
Free
Visit Website

Full-featured C2 framework which silently persists on webserver via polymorphic PHP oneliner. The obfuscated communication is accomplished using HTTP headers under standard client requests and web server's relative responses, tunneled through a tiny polymorphic backdoor: <?php @eval($_SERVER['HTTP_PHPSPL01T']); ?> Efficient: More than 20 plugins to automate privilege-escalation tasks. Run commands and browse filesystem, bypassing PHP security restrictions. Upload/Download files between client and target. Edit remote files through local text editor. Run SQL console on target system. Spawn reverse TCP shells. Stealth: The framework is made by paranoids, for paranoids. Nearly invisible by log analysis and NIDS signature detection. Safe-mode and common PHP security restrictions bypass. Communications are hidden in HTTP Headers. Loaded payloads are obfuscated to bypass NIDS. http/https/socks4/socks5 Proxy support. Convenient: A robust interface with many crucial features. Detailed help for any optio

FEATURES

ALTERNATIVES

Small script to simplify format string exploitation.

Using Apache mod_rewrite as a redirector to filter C2 traffic for Cobalt Strike servers.

A simple SSRF-testing sheriff written in Go

Interactive online malware sandbox for real-time analysis and threat intelligence

Using Apache mod_rewrite rules to rewrite incident responder or security appliance requests to an innocuous website or the target's real website.

A full-featured reconnaissance framework for web-based reconnaissance with a modular design.

A collection of payloads and methodologies for web pentesting.

A Python-based tool for identifying and exploiting file inclusion and directory traversal vulnerabilities in web applications.