Re: custom xp_cmdshell on SQL Server
- From: "Zed Qyves" <zqyves.spamtrap@xxxxxxxxx>
- Date: Thu, 14 Sep 2006 10:28:14 +0300
I would recommend against it...
Why don't you reload it (That is if someone hasn't revoked O/S user
privileges on the DLL)?
From the help file:
sp_addextendedproc [@functname =] 'procedure',
[@dllname =] 'dll'
Arguments
[@functname =] 'procedure'
Is the name of the function to call within the dynamic-link library
(DLL). procedure is nvarchar(517), with no default. procedure
optionally can include the owner name in the form owner.function.
[@dllname =] 'dll'
Is the name of the DLL containing the function. dll is varchar(255),
with no default.
So....
exec master.sp_addextendedproc @functname='xp_cmdshell', @dllname
='xpstar70.dll'
Check the DLL name I am not sure if this (xpstar70.dll) is the correct
one, its been a while since I got my hands dirty :)
Z
------------------------------------------------------------------------
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
------------------------------------------------------------------------
- Follow-Ups:
- User group tool
- From: Bud Gordon
- User group tool
- Prev by Date: RE: tools to scan source code
- Next by Date: Pentest SAP
- Previous by thread: RE: custom xp_cmdshell on SQL Server
- Next by thread: User group tool
- Index(es):
Relevant Pages
|