Open cardosec

Case BB6BC1 · Web AppSec · L3 Applied

Web Shell in Uploads Folder

Practise as: Incident drill

Live alertEDR on web-02 flags w3wp.exe spawning cmd.exe running whoami at 14:40; a new file avatar.aspx appeared in /uploads/ ten minutes earlier.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. IIS worker process spawning a shell is a high-fidelity web shell indicator; treat host as compromised
  2. Isolate web-02 via EDR, pull it from the load balancer, and preserve memory, IIS logs and the dropped file
  3. Trace the upload: IIS logs for the POST that wrote avatar.aspx, source IP, and all later requests to it
  4. Hunt siblings: other new .aspx/.ashx files, new local accounts, scheduled tasks, and credential access on the host
  5. Fix upload handling: extension/content allowlist, store outside webroot, no execute permission on upload dir

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.