参考网址:xp_cmdshell
1. 权限
由于恶意用户有时尝试使用 xp_cmdshell 提升其权限,因此默认情况下 xp_cmdshell 处于禁用状态。(1) 启用xp_cmdshell
-- To allow advanced options to be changed.
EXECUTE sp_configure 'show advanced options', 1;
GO
-- To update the currently configured value for advanced options.
RECONFIGURE;
GO
-- To enable the feature.
EXECUTE sp_configure 'xp_cmdshell', 1;
GO
-- To update the currently configured value for this feature.
RECONFIGURE;
GO
(2) 关闭xp_cmdshell
-- To allow advanced options to be changed.
EXECUTE sp_configure 'show advanced options', 1;
GO
-- To update the currently configured value for advanced options.
RECONFIGURE;
GO
-- To enable the feature.
EXECUTE sp_configure 'xp_cmdshell', 0;
GO
-- To update the currently configured value for this feature.
RECONFIGURE;
GO
2. 释义
生成 Windows 命令 shell 并以字符串的形式传递以便执行。任何输出都作为文本的行返回。
3. 应用
执行指定路径下的EXE文件
exec master..xp_cmdshell 'c:/aa.exe'