Case BB6BC1 · Web AppSec · L3 Applied
Web Shell in Uploads Folder
Practise as: Incident drill
Live alertEDR on web-02 flags w3wp.exe spawning cmd.exe running whoami at 14:40; a new file avatar.aspx appeared in /uploads/ ten minutes earlier.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- IIS worker process spawning a shell is a high-fidelity web shell indicator; treat host as compromised
- Isolate web-02 via EDR, pull it from the load balancer, and preserve memory, IIS logs and the dropped file
- Trace the upload: IIS logs for the POST that wrote avatar.aspx, source IP, and all later requests to it
- Hunt siblings: other new .aspx/.ashx files, new local accounts, scheduled tasks, and credential access on the host
- Fix upload handling: extension/content allowlist, store outside webroot, no execute permission on upload dir
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.