Author: 0 xAINI www.anying.org must indicate the author and the shadow technical team website.
A South Korean gambling site first
I don't even know how to play Korean games. Not some friends say this is a gambling site. I don't even know how to clean it.
Let's take a rough look.
Open a page to test the injection point.
Well, it seems that there are no injection points, but there is another injection detection method.
This is an error.
Now let's guess the number of Columns
Okay, there are 13 columns in total. Now we need to collect the target information.
Nima is MYSQL4! This is amazing!
The storm database is no longer possible. Just like running ACC, my dictionary is not powerful enough and there are no foreign dictionaries.
But what should I do if I have ROOT permissions?
Based on the previous detection, it can be determined that the magic quotation marks are not opened.
Then try to write SHELL.
If you have the ROOT permission and the magic quotes are closed, can MYSQL4 write files?
For this reason, I specifically went to xilaiyunxiao to ask
I decided to give it a try to prove it.
The problem is that this station does not have a physical path. What should I do ??
Then we can find a path to use various informal access methods.
Then try the tricky test.
Http://www.xxx.com/board1/board_cntn1.php? Postno = 34 'Union all select, into outfile 'C:/html/soju/common/a. php '/*
OK. Try again.
After the test is passed, write a sentence and then there will be no more