Detect ShellInABox
Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator.
Detection looks at javascript globals, html markup across 3 fingerprint rules among the site's public responses.
01
Websites using ShellInABox
Loading website list…
02
Signal classes
PluginView evaluates public page signals in these classes when identifying ShellInABox. Individual fingerprint rule bodies are proprietary and are not published.
- JavaScript globals
- HTML markup
03
Example public indicators for ShellInABox
Illustrative indicators derived from public catalog metadata for ShellInABox. A live scan may match additional proprietary rules beyond these examples.
- ShellInABox
- <title>Shell In A Box</title>
- must be enabled for ShellInABox</noscript>
04
What a detection means
- Establishes
- One or more public signals on the scanned page matched a known ShellInABox signature (3 rules) at the time of the scan.
- Does not establish
- A sitewide install of ShellInABox, an active vendor contract, exclusive use, or that ShellInABox is still in place today.
05
How to check a site for ShellInABox
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest ShellInABox signals.
- 2. PluginView reads only public responses (javascript globals, html markup) and scores them against the ShellInABox signature set (3 rules).
- 3. Review the confidence score and text explanation for ShellInABox on the results page.
06
FAQ: detecting ShellInABox
- Can PluginView detect ShellInABox without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for ShellInABox — typically javascript globals, html markup. It does not bypass authentication or paywalls.
- What category is ShellInABox?
- ShellInABox is classified under Remote access in the PluginView directory.
- How many fingerprint rules cover ShellInABox?
- This reference currently tracks 3 fingerprint rules across javascript globals, html markup. Individual rule bodies are proprietary and are not published.
- What public signals suggest a site uses ShellInABox?
- Illustrative public indicators for ShellInABox include ShellInABox; <title>Shell In A Box</title>; must be enabled for ShellInABox</noscript>. A live scan may match additional proprietary rules beyond these examples.