Skip to content

sag-asab/PHP-Web-Shells

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

3 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

PHP-Web-Shells

๐Ÿš PHP Web Shells - Lightweight Bypass Collection

A collection of lightweight, stealthy PHP web shells designed for penetration testing and security assessments. These shells are optimized to bypass common security filters, WAFs (Web Application Firewalls), and antivirus signatures while maintaining a small footprint.


โšก Features

  • Lightweight โ€“ Minimal code size (most under 2KB) for fast uploads and execution.
  • Bypass Capabilities โ€“ Evades:
    • eval() / system() blacklists
    • Base64 & string obfuscation filters
    • Common WAF rules (ModSecurity, Cloudflare, etc.)
    • Signature-based AV detection
  • Stealth Mode โ€“ Disguised as harmless PHP files (e.g., image.php, 404.php).
  • Multiple Payloads โ€“ Includes various encoding techniques (hex, gzip, XOR, ROT13).
  • Simple Commands โ€“ Supports cmd, exec, file_put_contents, and file manager functionality.

๐Ÿ“ข Join Our Community

Stay updated with new bypass techniques, fresh shells, and security research:

Telegram Channel

๐Ÿ”” Don't miss out! Get instant access to exclusive payloads, updates, and tips.