Malware
Webshell
Webshell is a small script uploaded to a web server that lets an attacker run commands or manage files through a browser request. It is how a one-time hole becomes lasting access.
How it is measured
Find it by looking for files that should not be there: PHP in upload folders, names like wp-cache.php or xmlrpc2.php, recent modification times, and code using eval, system, passthru, or base64_decode on request input. Compare the tree with a clean copy of core and plugins.
Logs help: requests to a single odd file with POST bodies, a long run of requests from one IP, responses with unusual sizes. The first request to the file is the point to work backwards from.
Worked example
A site's host reports a shell. In /wp-content/uploads/2024/ there is a file named .htaccess.php, 6 KB, that reads a password from $_POST['k'] and then runs system on a second field. Access logs show 412 POSTs to it from three IPs, starting at 03:07 on 14 June.
The request just before the file's creation is a POST to an old slider plugin. Deleting the file closes one door; removing the plugin and checking for a second shell, which turns up in the theme's 404.php, closes the rest.
How it differs
A backdoor is any hidden way to get back in; it could be an extra account or a modified login function. A webshell is a particular kind that gives a command interface over HTTP. All webshells are backdoors; not all backdoors are webshells.
Common errors
Deleting the shell the scanner found and stopping there. Searching only by filename. Forgetting to look in uploads, cache, and theme folders. Not changing database and admin passwords. Allowing PHP execution in the uploads directory.
In practice
Block script execution in uploads and cache folders, set file permissions so the web user cannot write to code directories, and run a file-integrity check on a schedule. After finding one, use the logs to find the entry point and look for more than one shell.