Collected research
Pulling system32 out over blind SQL Injection
A route out of a blind SQL injection where xp_cmdshell also gives no feedback, no outbound traffic is allowed and the webroot path is unknown. Echo a VBS file line by line through xp_cmdshell, run it with cscript, and it creates an IIS virtual directory 'secret' mapped to %windir% with execute permission; /secret/system32/cmd.exe then runs commands over HTTP. Metasploit sketch included.
Record
- Researcher
- Shreeraj Shah
- Published by
- blueinfy.com
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Shreeraj Shah, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .