---
title: "Defending Against WebShell Attacks"
description: "Notes from investigating and handling a WebShell Attack security incident, covering IIS directory permission review, removing unnecessary script engines, and Windows security updates as preventive measures."
canonical_url: "https://blog.markkulab.net/en/post/webshellattack"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2020-12-21 15:01:35 +0300"
category: "Security"
tags: ["security", "webshell", "iis", "asp.net", "hacking", "windows"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# Defending Against WebShell Attacks

## Handling a Security Incident

While investigating a security incident, we found that an attacker had left a backdoor script on the server, and the site's JS had been tampered with to redirect users to a fake Flash page. After looking into it, I suspected we'd been hit by a WebShell attack.

## What is a WebShell Attack?

![WebShell attack diagram showing attacker uploading and executing malicious scrip](https://blog.markkulab.net/content/markku/posts/webshellattack/images/webshellattack.png)

Looking at the diagram on the cover image, attackers may have used vectors like:

vulnerabilities in Microsoft products (Windows, IIS, .NET Framework), or an employee's infected machine being used as a stepping stone,

combined with overly broad write permissions on the web server,

to drop a prepared backdoor script

into our web server.

Because the web script engine recognizes the script,

simply opening the page is enough to execute it.


## Questions

Looking at this as a developer, a lot of questions came up.

Why did some process have permission to modify our code?

Why is this script even able to run on the server?

Don't we use MVC across the company now? Why is the ASPX engine still around?

## Simulating the Scenario
After going through a lot of references, I wrote a PoC script (ASPX) to simulate the situation.
Since I couldn't simulate how the file got in, I uploaded it manually instead, and confirmed that the code could indeed write arbitrary files.

```
<%@ Page Language="C#" %>
<%@ Import Namespace="System"%>
<%@ Import Namespace="System.IO"%>
<%@ Import Namespace="System.Text"%>

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<script runat="server">


        protected void Page_Load(object sender, EventArgs e)
        {
			
			  string currentdir =  HttpContext.Current.Server.MapPath("~")
              string path = currentdir + "/HackTest.txt";


            
                // Create the file, or overwrite if the file exists.
                using (FileStream fs = File.Create(path))
                {
                    byte[] info = new UTF8Encoding(true).GetBytes("This is some text in the file.");
                    // Add some information to the file.
                    fs.Write(info, 0, info.Length);
                }

                // Open the stream and read it back.
                using (StreamReader sr = File.OpenText(path))
                {
                    string s = "";
                    while ((s = sr.ReadLine()) != null)
                    {
                        Console.WriteLine(s);
                    }
                }
			
		}

</script>

<html xmlns="http://www.w3.org/1999/xhtml">
<head runat="server">
    <title></title>
</head>
<body>

</body>
</html>
```

In the end, after reading Will's [blog post](https://blog.miniasp.com/post/2009/03/16/IIS-6-Identity-and-Windows-Access-Control-is-not-what-you-expected), I found that IIS's default directory is safe, but once we moved it to drive X, it inherited the extra permissions from drive X. Sure enough, our IIS directory was both writable and modifiable.

## My Final Solution
1. Remove unnecessary script engines from web.config (ASPX, ASP, ...).
1. Review IIS directory permissions and disable inheritance from drive D — restrict users to read-only, with no script execution or write access.
1. Review the IIS Request Filtering settings.
1. Run Windows Update at least every six months. Apply patches early when Microsoft publishes major security advisories. You can check the [Windows Update guide site](https://msrc.microsoft.com/update-guide) for major security vulnerabilities.

## References
[IIS execution identity and Windows access control aren't what you think](https://blog.miniasp.com/post/2009/03/16/IIS-6-Identity-and-Windows-Access-Control-is-not-what-you-expected)
[How to Secure a Site in IIS](https://www.liquidweb.com/kb/how-to-secure-a-site-in-iis/)
[Government Configuration Baseline (GCB) IIS 8.5](https://download.nccst.nat.gov.tw/attachfilegcb/02.108%E5%B9%B4GCB%E5%AF%A6%E4%BD%9C%E7%A0%94%E7%BF%92%E6%B4%BB%E5%8B%95_Microsoft%20IIS%208.5%E7%B5%84%E6%85%8B%E8%A8%AD%E5%AE%9A%E8%88%87%E5%AF%A6%E4%BD%9C%E7%B7%B4%E7%BF%92v1.0_1081111.pdf)
[Government Configuration Baseline rollout and assessment tool](https://www.4mosan.com/product/gcb-tw.php)
[.NET Security Application/Web Development - Overview](https://www.slideshare.net/chentientsai/net-security-applicationweb-development-overview)
[.NET Security Application/Web Development - Overview - 2](https://www.slideshare.net/chentientsai/net-security-applicationweb-development-part-ii)
[.NET Security Application/Web Development - Overview - 3](https://www.slideshare.net/chentientsai/net-security-applicationweb-development-part-iii)
[.NET Security Application/Web Development - Overview - 3](https://www.slideshare.net/chentientsai/net-security-applicationweb-development-part-iv-129410445)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/webshellattack)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
