
PHPsploit
A PHP-based command and control framework that maintains persistent web server access through polymorphic backdoors and HTTP header communication tunneling.

PHPsploit
A PHP-based command and control framework that maintains persistent web server access through polymorphic backdoors and HTTP header communication tunneling.
PHPsploit Description
PHPsploit is a command and control (C2) framework designed for maintaining persistent access to web servers through PHP-based backdoors. The framework operates by deploying a polymorphic PHP one-liner backdoor that communicates through HTTP headers to avoid detection. The tool includes over 20 plugins for automating privilege escalation tasks and bypassing PHP security restrictions. Core functionality includes remote command execution, filesystem browsing, file upload and download capabilities, remote file editing through local text editors, SQL console access, and reverse TCP shell spawning. PHPsploit incorporates stealth features such as obfuscated payload delivery, HTTP header-based communication tunneling, and support for HTTP/HTTPS/SOCKS4/SOCKS5 proxies. The framework is designed to evade log analysis and network intrusion detection system (NIDS) signature detection while operating within PHP safe-mode and other common security restrictions. The interface provides detailed help documentation and robust command-line functionality for managing compromised web servers and executing post-exploitation activities.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.