An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?
A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.
Why this answer
The file shell.aspx contains code that accepts commands via HTTP POST and executes them on the server, which is the classic definition of a webshell. A webshell is a malicious script uploaded to a web server that provides an attacker with remote command execution capabilities, often used for persistence and post-exploitation activities.
Exam trap
EC-Council often tests the distinction between attacks that involve direct server-side code execution (webshell) versus attacks that manipulate other systems or users (SSRF, CSRF) or exploit database layers (SQL injection), so candidates must focus on the presence of an uploaded executable script file.
How to eliminate wrong answers
Option A is wrong because Server-Side Request Forgery (SSRF) involves the server making requests to internal or external resources on behalf of the attacker, not executing arbitrary commands via a file in the uploads directory. Option B is wrong because SQL injection exploits vulnerabilities in database queries, not the execution of system commands through an uploaded script file. Option D is wrong because Cross-Site Request Forgery (CSRF) tricks a user's browser into performing unintended actions on a trusted site, not directly executing commands on the server via an uploaded file.