Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to write Shell read files by Mysql injection

Shulou Source: shulou.com Published: 2022-06-01 00:10:51 10月03日 Update

Editor to share with you how to write Mysql injection Shell reading files, I hope you will learn something after reading this article, let's discuss it together!

First, export the function to write shell

Directly write an accessible webshell by using the export function of Mysql

1.1 conditions

1. The absolute path to the accessible path of the website

Error

Enter an exception value to cause the script to report an active error, or the foot error message of the googlehacking target

Phpinfo

Scan the catalog for phpinfo

Speculate

The target may use an integrated installation package, such as phpstudy

C:\ phpStudy\ WWW\ C:\ phpStudy\ WWW\ domain name\

Enumerate

High frequency absolute path

Read the configuration file

Middleware, configuration file for web

The value of 2.secure_file_priv is not NULL or contains the absolute path of the export

The value of secure_file_priv is set in the mysql configuration file my.ini, which is used to restrict data import and export

Mysql > = 5.5.53 defaults to NULL, that is, import and export are prohibited by default

Mysql

Tags: Logs files paths queries permissions functions statements quotes data websites scripts presentations success users coding configuration packages time directories escape Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn Apple macOS Xiaomi Shulou Information