Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

MySQL 5.1ÍêÈ«Ð¶ÔØ

ÓÉÓÚ°²×°MySQLµÄʱºò£¬ÊèºöûÓÐÑ¡Ôñµ×²ã±àÂ뷽ʽ£¬²ÉÓÃĬÈϵÄASCIIµÄ±àÂë¸ñʽ£¬ÓÚÊǽӶþÁ¬ÈýµÄÖÐÎÄת»»ÎÊÌâËæÖ®¶øÀ´£¬¾ÍÏëÐ¶ÔØÁËÖØÐ°²×°MYSQL£¬ÕâÒ»Ð¶ÔØµ¹ÊdzöÁËÎÊÌ⣬µ¼Ö°²×°µÄʱºò°²×°²»ÉÏ£¬ÔÚÍøÉÏÕÒÁËÒ»¸ö¶àСʱҲû½â¾ö¡£
ÖØ×°ÏµÍ³ÓÀÔ¶ÊǸöºÃ°ì·¨£¬µ«ÓÐ˭ϲ»¶Õâô×öѽ:(
ºóÀ´ÎÞÒâ·¢ÏÖÊÇÐ¶ÔØµÄʱºòûÓÐÐ¶ÔØÍêÈ«µ¼Ö£¬ÏÂÃæ¸ø³öÍêÕûµÄÐ¶ÔØMySQL 5.1µÄÐ¶ÔØ·½·¨£º
1¡¢¿ØÖÆÃæ°åÀïµÄÔö¼Óɾ³ý³ÌÐòÄÚ½øÐÐɾ³ý
2¡¢É¾³ýMySQLÎļþ¼ÐϵÄmy.iniÎļþ£¬Èç¹û±¸·ÝºÃ£¬¿ÉÒÔÖ±½Ó½«Îļþ¼ÐÈ«²¿É¾³ý
3¡¢¿´¿´×¢²á±íÀïÕ⼸¸öµØ·½É¾³ýûÓÐ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\MySQL Ŀ¼ɾ³ý
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\MySQL Ŀ¼ɾ³ý
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\MySQL Ŀ¼ɾ³ý
4¡¢ÕâÒ»ÌõÊǺܹؼüµÄ
C:\Documents and Settings\All Users\Application Data\MySQL
ÕâÀﻹÓÐMySQLµÄÎļþ£¬±ØÐëҪɾ³ý
×¢Ò⣺Application DataÕâ¸öÎļþ¼ÐÊÇÒþ²ØµÄ£¬ÐèÒª´ò¿ª¸öÎļþ¼ÐÑ¡Ôñ²Ëµ¥À¸ ¹¤¾ß→Îļþ¼ÐÑ¡Ïî→²é¿´→Òþ²ØÎļþºÍÎļþ¼Ð Ò»ÏîÑ¡ÉÏ ÏÔʾËùÓÐÎļþºÍÎļþ¼Ð È·¶¨
OK£¡ÒÔÉÏ4²½Íê³É£¬Ôٴΰ²×°°É£¬ºÙºÙ£º£©


Ïà¹ØÎĵµ£º

[Injection]¶ÔMYSQL 5.0·þÎñÆ÷ÒÔÉϰ汾עÈë


by ZaraByte
How to do a SQL Injection for MYSQL Server 5.0+
1. Find a vulnerable add a ‘ at the end of the site example: news.php?id=1 add a ‘ at the end of the 1 and see if you get a syntax error
2. order by #–
Keep upping the # until you get an error.
3. union all select 1 ......

ÔÚmysqlÊý¾Ý¿âÖÐÈÕÆÚÓëlongÐ͵Äת»¯

1¡¢ÔÚmysql Êý¾Ý¿âÖУ¬“2009-09-15 00£º00£º00”ת»¯ÎªÁÐΪ³¤ÕûÐ͵ĺ¯Êý£º
select unix_timstamp("2009-09-15 00£º00£º00")*1000,
ÕâÀïҪעÒ⣬mysqlÊý¾Ý¿âÖеij¤ÕûÐÍ£¬±ÈjavaÖеij¤ÕûÐÍÉÙÁËÃëºóÃæµÄºÁÃëÊý£¬ËùÒÔÒª³ËÒÔ1000£¬ÕâÑùÖ»Óм¸ºÁÃëÖ®²î
2¡¢ÔÚmysqlÊý¾Ý¿âÖУ¬“1252999488000”£ ......

¸ü¸ÄMySqlÊý¾Ý¿âµÄĬÈϱàÂë¸ñʽ

Ò»¡¢ÉèÖÃÊý¾Ý¿â±àÂë
°²×°mysqlʱ¿ÉÑ¡Ôñ±àÂ룬Èç¹ûÒѾ­°²×°¹ý£¬¿ÉÒÔ¸ü¸ÄÎļþmy.ini(´ËÎļþÔÚmysqlµÄ°²×°Ä¿Â¼ÏÂ)ÖеÄÅäÖÆÒԴﵽĿµÄ£»´ò¿ªÎļþÕÒµ½Á½´¦£º
[client]
port=3306
[mysql]
default-character-set=gb2312
# The default character set that will be used when a new
schema or table is
# created and
n ......

MysqlÊý¾ÝÌáÈ¡Æ÷

        ¼¸¸öÔÂǰ£¬ÊÜһλÀÏʦµÄίÍУ¬Òª°ïËû×öÒ»¸ö¹ØÏµÊý¾Ý¿âģʽÐÅÏ¢ÌáÈ¡µÄСÏîÄ¿£¬Ö÷ÒªµÄ¹¦ÄÜʵÏÖ¾ÍÊǽ«¹ØÏµÊý¾Ý¿âµÄ±í½á¹¹ºÍ×ֶεÄÐÅϢͨ¹ý±í¸ñµÄÐÎʽչʾ³öÀ´¡£ÎÒͨ¹ý´ÓÍøÉÏËѼ¯×ÊÁÏÒÔ¼°·­Êé²éÕÒ£¬ÏÈʵÏÖÁËÒ»¸ömysqlµÄÊý¾ÝÌáÈ¡Æ÷¡£Ïȸø´ó¼Ò·ÖÏíһϡ£ÉÔºóµÄ¼¸ÌìÄÚ»á°ÑÁíÒ»¸ömysql¹ ......

ÐÞ¸ÄMySQLĬÈÏÃÜÂëµÄ¾ßÌå²½Ö裨ת£©

access denied for user 'root'@'localhost' (using password: YES);
½ñÌìÓÃmysqlµÄʱºò£¬µÇ¼µÄʱºò³öÏÖÁËÕâ¾ä£¬²»ÖªµÀÊÇʲôÒâ˼£¬ÒòΪÎÒµÄmysqlÊÇ×°centosµÄʱºòÒ»Æð×°µÄ£¬ÃÜÂëÎÒ¾ÍÊäÈëÎÒµÄÕÊ»§ÃÜÂ룬½á¹û³öÏÖÁËÉÏÃæÄǾ䣻°Ù¶ÈÁËһϣ¬»¹Õæ²»ÉÙÈ˳öÏÖÁËÕâ¸öÎÊÌâ¡£¡£×îºóÎÒÕÒµ½ÁË·½·¨£»
[root@localhost home]# mysql - ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ