The idea of obtaining webshell for sa permission
The idea of obtaining webshell for sa permission
1. Through the SQL query Analyzer, the xp_cmdshell stored procedure is first restored with sa permissions.
two。 Connect to the database through SQL Tools2.0, execute commands, view the site path and disk files, and get the real path of the site.
3.echo generates a sentence back door.
4. Get webshell permissions directly.
5. If a sentence generated by echo cannot be executed at the backdoor, you can check the database of the corresponding website, obtain the login password in the background, and upload the jpg of webshell through the background. Then copy the jgp file to the aspx file through the copy command to get the webshell.
Tips:
1. Look for writable folders, such as c:/windows/temp, and the true drive of the site.
two。 Generate a sentence back door through the echo command
Echo ^ > d:\ wwwroot\ ok.asp
Echo ^