PHP+MYSQL?

There are two simple methods to get a webshell without using "select
into outfile":

One is getting the administrator's infomations from the database,then
entering the management,and trying to upload a webshell;

The other is not thinking database at all and trying find a place to
include~


On 3月5日, 下午1时09分, zhuzhu <[email protected]> wrote:
> Hi all,
>
>    These days I am trying to hack a web site with sql injection
> weakness. It seems that the database and the web pages are hosted on
> two different machines. I don't know how to get the webshell in this
> case. Is there any way to get the ip address of the mysql server so
> that I could do some further exploration?

--~--~---------~--~----~------------~-------~--~----~
 要向邮件组发送邮件,请发到 [email protected]
 要退订此邮件,请发邮件至 [email protected]
-~----------~----~----~----~------~----~------~--~---

回复