Binary Webshell Through OPcache in PHP 7

OPcache is the new built-in caching engine with PHP 7.0. It compiles PHP scripts and sets the resulting bytecode in memory. It also offers caching in the filesystem when specifying a destination folder in your PHP.ini

This attack can only be executed if an existing file upload vulnerability exists, for example through a vulnerable WordPress plugin. That is why frequent security assessments of your content management system, such as WordPress, is important.

Leave a Reply

Your email address will not be published.