Skip to content

feat: Expand web shells (v1)#4626

Open
HackingRepo wants to merge 5 commits into
coreruleset:mainfrom
HackingRepo:patch-9
Open

feat: Expand web shells (v1)#4626
HackingRepo wants to merge 5 commits into
coreruleset:mainfrom
HackingRepo:patch-9

Conversation

@HackingRepo
Copy link
Copy Markdown
Contributor

What?

Expanded web shells, to add new entries

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 26, 2026

📊 Quantitative test results for language: eng, year: 2023, size: 10K, paranoia level: 1:
🚀 Quantitative testing did not detect new false positives

Copy link
Copy Markdown
Member

@EsadCetiner EsadCetiner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your grouping together a lot of different shells under Unknown web shell such as r57 shell, don't group them as Unknown web shell if they're known.

There are also a lot of really generic entries here like:

<center><b>Command history</b><br></center>

Please try to be as specific as you can.

Comment thread rules/web-shells-php.data
@HackingRepo HackingRepo requested a review from EsadCetiner May 1, 2026 07:38
Comment thread rules/web-shells-php.data
<input type=submit name=find value='find writeable'>
<div align="center">code Author:<span class="STYLE1"><font color='red'> 仗剑孤行 QQ:87074139</font></span></div>

# From https://github.com/xl7dev/WebShell/blob/master/Php others
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This comment isn't very helpful, can you please copy the format that the above entries use?

Comment thread rules/web-shells-php.data
<title> nShell
<title>Win MOF Shell</title>
<title> Matamu Mat </title>
<title>lostDC -
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is way too generic, can you be more specific here?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants