Attack chain 8 steps

Exposed Endpoint to Web Shell

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    An exposed admin endpoint or file-upload feature is discovered during enumeration.

  2. 2

    Step 2 of 8

    Weak validation is tested and found to accept a file with a server-side extension.

  3. 3

    Step 3 of 8

    The uploaded file is requested directly, returning execution output and confirming code execution.

  4. 4

    Step 4 of 8

    A more capable shell with a randomised name is uploaded for persistence.

  5. 5

    Step 5 of 8

    Server configuration files are read to obtain database credentials.

  6. 6

    Step 6 of 8

    Credentials are reused against other internal systems where passwords are shared.

  7. 7

    Step 7 of 8

    Outbound command-and-control traffic is established using a legitimate protocol such as HTTPS.

  8. 8

    Step 8 of 8

    The host becomes a pivot point for further lateral movement across the network.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used