PHPsploit
A PHP-based command and control framework that maintains persistent web server access through polymorphic backdoors and HTTP header communication tunneling.

PHPsploit
A PHP-based command and control framework that maintains persistent web server access through polymorphic backdoors and HTTP header communication tunneling.
PHPsploit Description
PHPsploit is a command and control (C2) framework designed for maintaining persistent access to web servers through PHP-based backdoors. The framework operates by deploying a polymorphic PHP one-liner backdoor that communicates through HTTP headers to avoid detection. The tool includes over 20 plugins for automating privilege escalation tasks and bypassing PHP security restrictions. Core functionality includes remote command execution, filesystem browsing, file upload and download capabilities, remote file editing through local text editors, SQL console access, and reverse TCP shell spawning. PHPsploit incorporates stealth features such as obfuscated payload delivery, HTTP header-based communication tunneling, and support for HTTP/HTTPS/SOCKS4/SOCKS5 proxies. The framework is designed to evade log analysis and network intrusion detection system (NIDS) signature detection while operating within PHP safe-mode and other common security restrictions. The interface provides detailed help documentation and robust command-line functionality for managing compromised web servers and executing post-exploitation activities.
PHPsploit FAQ
Common questions about PHPsploit including features, pricing, alternatives, and user reviews.
PHPsploit is A PHP-based command and control framework that maintains persistent web server access through polymorphic backdoors and HTTP header communication tunneling.. It is a Security Operations solution designed to help security teams with Post Exploitation, C2, PHP.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.
Weekly cybersecurity newsletter for security leaders and professionals