security: Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments

· Sujith Quintelier · April 2, 2026, 5:38 p.m.
Summary
The blog post discusses a stealthy technique for exploiting PHP webshells in Linux hosting environments using HTTP cookies for operation control. It outlines methods for obfuscation, execution via php-fpm, and cron-based persistence that help attackers remain undetected. The content seems to be a brief overview of a security issue as described by Microsoft, shedding light on tactics that could potentially compromise server security.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →