Posted by Seanybob on Apr 06
The c100 shell (and likely several of the shells) available at
t00ls.org(which is one of the top ranked sites for various
shell-related google
searches, e.g. "c99
php<http://www.google.com/search?hl=en&rlz=1C1CHFX_enUS372US372&q=c99+php&aq=f&aqi=g3g-v7&aql=&oq=>")
has a callback hidden within its code that contacts the site and lets them
know where you installed the c100 shell.
The backdoor code is…




