Malware

Backdoor

Backdoor is a hidden way into a system that skips the normal login. On a website it is usually a small file or code hook an attacker leaves behind so they can return after you patch the original hole.

How it is measured

You find a backdoor by looking for code that accepts commands without authentication: a PHP file that reads `$_POST` into `eval`, a rogue admin user, an SSH key in `authorized_keys` you did not add, or a cron job that re-downloads a file. File integrity checks against a clean copy of core and plugins catch most of them.

Check modification times, not just content. A `wp-includes` file touched last Tuesday while the rest are from the last release is the signal. Log lines showing a POST to an odd path such as `/wp-content/uploads/x.php` are the second signal.

Worked example

A WordPress shop cleans up after a defaced homepage. The owner updates the vulnerable gallery plugin and deletes the injected `index.php` edit. Nine days later the site is defaced again. A scan finds `wp-content/uploads/2024/03/img_cache.php`, 1.2 KB, which decodes a POST field and runs it.

The upload folder should never hold PHP. After the owner removes that file, also deletes a second admin account named `support_tech`, and rotates the database password, the defacements stop.

How it differs

A backdoor is the persistence. A webshell is one common form of it: a script that gives a browser-based command prompt. Not every backdoor is a webshell, since a stolen SSH key or a hidden admin account has no script at all. A rootkit goes lower and hides the backdoor from the operating system itself.

Common errors

Patching the original vulnerability and assuming the intruder is gone. Restoring from a backup taken after the first compromise. Deleting the one file you found without hunting for its siblings. Ignoring user accounts, scheduled tasks, and database options, which can all hold persistence. Trusting a filename like `class-wp-cache.php` because it looks like core.

In practice

After any compromise, assume at least one second way in exists. Diff core files against a fresh download, list admin users and cron jobs, search the uploads folder for executable extensions, and rotate every credential. Only then bring the site back.

See also

Webshell, Rootkit, Command and control

Sources

Count this on a real site.

Watch my website