Penetration Testing mailing list archives
Re: Reconfiguring cmdshell
From: 596 <infosecurity.email () gmail com>
Date: Sat, 30 Jun 2012 23:49:26 -0700
Reminds me of an old American Indian proverb - if you see a small bear in the woods don't be happy, there is always a bigger bear behind it. "Beware of the next level". - 596 On Jun 30, 2012, at 12:06 PM, Smiling Buddha wrote:
Hi, I am on a pentest assignment and have encountered an sql injection vulnerability with an SQL Server 2005 in the background, complete with dbo level access. I have successfully retrieved DB values and have already presented as evidence. Now, i am directed to take the attack to the next level and see the extent of the problem. I am trying to run the xp_cmdshell stored procedure. To ensure xp_cmdshell is enabled, i am running the following two queries: EXEC master..sp_configure 'xp_cmdshell', '1' RECONFIGURE in the vulnerable parameter as: ';EXEC master..sp_configure 'xp_cmdshell', '1'' - This query replies without any error But when i append RECONFIGURE the following it returns an error: ';EXEC master..sp_configure 'xp_cmdshell', '1';RECONFIGURE' - Incorrect syntax near " I looked up the sp_configure functionality and don't see any syntactical error, maybe the sequence, or incorrectly formed stacked query. Any suggestions? Thanx. ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- Re: Reconfiguring cmdshell 596 (Jul 02)
- <Possible follow-ups>
- Re: Reconfiguring cmdshell Yiannis Koukouras (Jul 02)