Not only is the idea completely nuts, but all Google produces for C99shell is how it's used in backdoor tools.
Surprises: Zero.
Not only is the idea completely nuts, but all Google produces for C99shell is how it's used in backdoor tools.
Surprises: Zero.
Of course, the better solution is to leave ASAP...
C99shell is easy to use and common.
Why is it nuts?? You're using it for quick and easy defacements and compromises.
This is a numbers game often from people with low skill levels. I see no issues here at all. If your defacements were getting quickly taken back by another crew it might be an issue, but I've seen no evidence of this happening.
Just because there's a security issue it's not the end of the world. Risk management still comes into it.
Easy to use = more defacements. Might have a hole, well is there evidence we are losing enough defacements to justify the retraining of the crew and added costs?
And more importantly, be agile. Defacements getting retaken over at unacceptable levels, just move to a different product.
Uploading PHP files with system() calls works too, but C99 is much easier to use.
But yes, I only came to know it when I was a stupid defacer teen. Shame on me.
(Answer: yes)
There are always reasons, sometimes valid reasons, to do insane things.