Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Jatayu — Stealthy standalone PHP web shell with HTTP header-based authentication, exec function switching, and undetectable design for remote command execution on web servers. | Kitploit
Tools/GitHubGitHub/spidermate/jatayu
Payload GenerationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubspidermate/jatayu

Jatayu

Stealthy standalone PHP web shell with HTTP header-based authentication, exec function switching, and undetectable design for remote command execution on web servers.

View Repository
3366 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Jatayu
JATAYU

Stealthy Stand Alone PHP Web Shell

FEATURES

  • Http Header Based Authentication.
  • 100% Undetectable.
  • Exec Function Changer.
  • Nothing Fancy

USAGE

root@kitploit:~
GET /test/jatayu.php?fn=1&&cmd=whoami
Host : http://test.com
Authtoken : bb3b1a1f-0447-42a6-955a-88681fb88499

FUNCTIONS

PARAMETERFUNCTION
fn=1Calls function shell_exec()
fn=2Calls function system()
cmd=idExecutes command

GENERATE AUTHTOKEN

root@kitploit:~
<?php
$r = unpack('v*', fread(fopen('/dev/random', 'r'),16));
$apiKey = sprintf('%04x%04x-%04x-%04x-%04x-%04x%04x%04x',
    $r[1], $r[2], $r[3], $r[4] & 0x0fff | 0x4000,
    $r[5] & 0x3fff | 0x8000, $r[6], $r[7], $r[8]);
echo $apiKey;
?>
Download Tool