News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Webshell and Anti-DDOS : hacking | Torhoo darknet markets

Hey everyone,

Not sure if this is the right place to post, so apologies in advance.

I was wondering if it's possible to put anti-DDoS protection (like Cloudflare or DDoS-Guard) on a web shell. I've seen some competitors who have somehow managed to get Cloudflare protection on theirs, but from my understanding, that's impossible to do without having control over the domain's DNS settings.

So, here's my noob question: How can you protect a web shell, and what kind of protection can you use?

Thanks.
/u/nyxara 🍼
1 points
1 week ago
u infiltrated an important place like a government agency, and I guess you don't want to lose the backdoor u created..

1. Use encryption: Use strong encryption to secure the backdoor and any data transferred through it.
2. Camouflage the backdoor as legitimate traffic: Use sophisticated techniques to make the backdoor appear as legitimate site data, so it won't be detected by network monitoring or other security measures.
3.limit the backdoor authority
these are the ones that came to my mind...
/u/must-kass 📢
1 points
6 days ago
Competitors are DDoSing me when I hit top 3 in Google SERP
/u/nyxara 🍼
1 points
6 days ago
Only that's all I could think of. If they are DDOS your system directly, you can change your system IP all the time, it's a bit tiring to lose track of it all the time, but you can counterattack if you want. After all, they started it first.
I don't know much, but I can search it up if you want?
/u/rmrf P sudo rm -rf /*
1 points
1 week ago
I am confused if it is a webshell is it not on the same domain that is already covered by the anti-ddos protection? Why would it be outside of this, maybe a subdomain? If this is the case you would need access to update the dns/network rules which you can do from the server but this might disrupt the entire host. You need access to the panel of the anti-ddos provider so you can modify rules to make it work.

I am not sure what value you get from putting it under the same anti-ddos rules because this would cause more analysis of your webshell .