Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?

⚠ Common exam trap

EC-Council often tests the distinction between the tool used to gain access (e.g., a file upload exploit) and the payload left behind (e.g., a web shell), causing candidates to confuse the exploit method with the resulting backdoor artifact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A web shell

The file 'shell.php' contains code that uses the PHP system() function to execute arbitrary operating system commands passed via the 'cmd' GET parameter. This is the classic definition of a web shell, which provides remote command execution on the server. It is not a SQL injection script, a file upload exploit, or a trojan in the traditional sense, as it directly accepts and runs system commands through HTTP requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A SQL injection script

    Why it's wrong here

    This artifact cannot be a SQL injection script because it contains no SQL syntax and performs no database interaction. SQL injection scripts exploit flawed query construction by submitting crafted input to a web application's database layer; they rarely exist as an uploaded file on the target server. The discovered file instead accepts HTTP parameters and passes them to OS command execution functions, which is the hallmark of a web shell, not a SQL-based attack tool.

  • ✗

    A file upload vulnerability exploit

    Why it's wrong here

    A file upload vulnerability exploit is the technique or tool that subverts upload validation to place an arbitrary file, whereas the discovered artifact is the file placed by such an exploit. In other words, the webshell is the payload, not the exploit itself. Identifying it as a file-upload exploit confuses the attack stage with the malicious entity found on the server; the artifact's own behavior, executing commands via HTTP, distinguishes it.

  • ✗

    A backdoor trojan

    Why it's wrong here

    Calling this a backdoor trojan is technically misleading because a trojan is usually a standalone executable or appended payload that creates a covert channel, whereas the artifact is a server-side script running inside the web server process. It does function as a backdoor, but the term is too broad to capture the specific HTTP-request-based, parameter-driven command execution mechanism. The precise classification for a script that offers an interactive command line over HTTP is 'web shell'.

  • ✓

    A web shell

    Why this is correct

    The artifact is a web shell: a server-side script (often PHP, ASPX, or JSP) that takes command strings from HTTP request parameters and executes them through functions such as system(), exec(), or Process.Start, then returns the output in the HTTP response. This gives the attacker a persistent, remote command-line interface on the web server whenever the script is accessible. Web shells are commonly uploaded via file upload vulnerabilities, then used for further compromise, credential harvesting, or pivoting inside the network.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.