The infrastructureshell · backdoor script

Web shell

A small script left on a compromised web server that turns an ordinary HTTP request into command execution. Often a single file, often named to blend into the application around it, and reachable by anyone who knows the path and the password.

Why it matters to you

It is a door, not a payload, and it usually outlives the vulnerability that installed it. Patching the entry point closes the way in and leaves the way back, so an intrusion that involved one is not over until the filesystem has been compared against a known-good state.

Where we meet it

Access is often resold rather than used, which is why a server can carry one quietly for months before anything happens on it. The gap between installation and use is where the defender's opportunity sits.

Where this term stops being vocabulary

Malveine is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.