CHFI Application, Email and Cloud Forensics Practice Question
While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?
⚠ Common exam trap
EC-Council often tests the distinction between the tool used to gain access (e.g., a file upload exploit) and the payload left behind (e.g., a web shell), causing candidates to confuse the exploit method with the resulting backdoor artifact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A web shell
The file 'shell.php' contains code that uses the PHP system() function to execute arbitrary operating system commands passed via the 'cmd' GET parameter. This is the classic definition of a web shell, which provides remote command execution on the server. It is not a SQL injection script, a file upload exploit, or a trojan in the traditional sense, as it directly accepts and runs system commands through HTTP requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A SQL injection script
Why it's wrong here
This artifact cannot be a SQL injection script because it contains no SQL syntax and performs no database interaction. SQL injection scripts exploit flawed query construction by submitting crafted input to a web application's database layer; they rarely exist as an uploaded file on the target server. The discovered file instead accepts HTTP parameters and passes them to OS command execution functions, which is the hallmark of a web shell, not a SQL-based attack tool.
- ✗
A file upload vulnerability exploit
Why it's wrong here
A file upload vulnerability exploit is the technique or tool that subverts upload validation to place an arbitrary file, whereas the discovered artifact is the file placed by such an exploit. In other words, the webshell is the payload, not the exploit itself. Identifying it as a file-upload exploit confuses the attack stage with the malicious entity found on the server; the artifact's own behavior, executing commands via HTTP, distinguishes it.
- ✗
A backdoor trojan
Why it's wrong here
Calling this a backdoor trojan is technically misleading because a trojan is usually a standalone executable or appended payload that creates a covert channel, whereas the artifact is a server-side script running inside the web server process. It does function as a backdoor, but the term is too broad to capture the specific HTTP-request-based, parameter-driven command execution mechanism. The precise classification for a script that offers an interactive command line over HTTP is 'web shell'.
- ✓
A web shell
Why this is correct
The artifact is a web shell: a server-side script (often PHP, ASPX, or JSP) that takes command strings from HTTP request parameters and executes them through functions such as system(), exec(), or Process.Start, then returns the output in the HTTP response. This gives the attacker a persistent, remote command-line interface on the web server whenever the script is accessible. Web shells are commonly uploaded via file upload vulnerabilities, then used for further compromise, credential harvesting, or pivoting inside the network.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.