ÈçºÎʹÓÃMySQLÌáÉýȨÏÞ
Ç°²»¾ÃÍøÉϹ«¿ªÁËÒ»¸öMySQL FuncµÄ©¶´,½²µÄÊÇʹÓÃMySQL´´½¨Ò»¸ö×Ô¶¨ÒåµÄº¯Êý,È»ºóͨ¹ýÕâ¸öº¯ÊýÀ´¹¥»÷·þÎñÆ÷¡£×îÔç¿´µ½Ïà¹ØµÄ±¨µÀÊÇÔÚo-otikÉÏ,µ«Êǹ«²¼µÄÊÇÕë¶Ô UnixϵͳµÄExploit,²¢Çҳɹ¦ÂÊÒ²²»ÊǺܸß.¶ø½üÆÚ,¹úÄÚÓиßÊַųöÕë¶ÔWinϵͳµÄÏà¹ØÎÄÕÂ,ÓÚÊÇÎÒÂíÉÏÕÒÀ´ÓëÅóÓÑһͬÑо¿.
ÆäʵÎÒÃÇÔç¾ÍÄÜÏëµ½.µ±ÎÒÃÇÔÚ¶ÔMSSQL\OracleÊý¾Ý¿â½øÐй¥»÷µÄʱºò,µÃµ½ÁË×îÊý¾Ý¿âÖиßȨÏÞµÄÕÊ»§,ÍùÍù¶¼ÊÇÖ´ÐÐÌØÊâµÄÀ©Õ¹¹ý³Ì»òÕߺ¯ÊýÀ´ ½øÐй¥»÷µÄ¡£±ÈÈçMSSQLÓÐXp_cmdshell,Oracle¿ÉÒÔͨ¹ýMsvcrt.dllÀ´´´½¨Ò»¸öÌØÊâµÄº¯Êý.¶øÎÒÃÇȴʼÖÕûÓÐÏëµ½,×÷ΪÁ÷ÐÐ µÄÊý¾Ý¿âÈí¼þÖ®Ò»µÄMySQL,Ò²ÊÇ¿ÉÒÔ½øÐк¯ÊýµÄ´´½¨µÄ.ÓÉ´Ë¿´À´,MySQLµÄÕâ¸ö©¶´²»Ó¦³ÆΪ©¶´¶ø½ö½öÊÇÒ»¸ö¼¼Êõ¶øÒÑ.
·Ï»°Ò»¶Ñ¹ýºó,ÎÒÃÇÀ´Á˽âÒ»ÏÂÔõôÔÚMySQLÀï´´½¨Ò»¸öº¯Êý°É.Õâ±ÈÈçºÎÀûÓÃÖØÒªÐí¶à,Ö»ÒªÁ˽âÁËÔÀí,ÔËÓþÍÄܸü¼ÓÁé»î,¶øÇÒ¿ÉÒÔÓëÆäËû˼ÏëÈÚ»á¹áͨ.
MySQLÖд´½¨Ò»¸öº¯ÊýµÄÓï¾äΪ:
Create Function FunctionName Returns [String|Integer|Real] Soname ‘C:\function.dll’;
ÆäÖÐFunctionNameÖ¸µÄÊǺ¯ÊýµÄÃû³Æ,C:\Function.DLLÖ¸µÄÊǺ¯ÊýËùµ÷ÓõÄDLL,¶øº¯ÊýÃûÕýÊÇDLLÖеĺ¯ÊýÃû³Æ.²»¹ýÕâÀï ÐèÒªÎÒÃÇ×¢ÒâµÄÊÇ,Èç¹ûÎÒÃÇÐèÒªMySQL¿ÉÒÔÔÚº¯ÊýÖ®Öи½´øÒ»¸ö²ÎÊýµÄ»°,ÄÇô¾ÍÒª·ûºÏUDFÐÎʽµÄ³ÌÐò±àд¹æÔò,¾ßÌåµÄ¿ÉÒԲ鿴MySQLÊÖ²áµÄµÚ 14½Ú:¡¶ÎªMySQLÔö¼Óк¯Êý¡·.¶øÆäÖÐSTRING,INTEGET,REALÊǺ¯ÊýÖ´ÐкóËù·µ»ØµÄÖµµÄÐÎʽ.µ±È»,ÎÒÃÇ´ó¿É²»±Ø×ñÑUDFÐÎʽµÄ ±àд,ÆäʵÈç¹ûÎÒÃǵĺ¯ÊýÖÐʹÓÃÒ»¸öÎÒÃÇÒªÖ´ÐеĴúÂë,¶ø²»Ê¹ÓòÎÊý,Ò»Ñù¿ÉÒÔ´ïµ½¹¥»÷µÄЧ¹û,±ÈÈç˵System(”command.com”)µÈµÈ. ÍøÉÏÏÖÔÚÒÔ´Ë©¶´½øÐй¥»÷µÄFurQÈä³æ¾ÍÊÇÒ»¸ö²»Ê¹ÓÃUDF¸ñʽµÄÀý×Ó.µ«ÊÇ×¢Òâ,Õâ¸ö´´½¨º¯ÊýµÄÓï¾ä±ØÐëÒªÇóÎÒÃÇËùÓõÄMySQLÕÊ»§ÓжÔmysql Õâ¸öÊý¾Ý¿âµÄдȨÏÞ,·ñÔòÎÞ·¨Õý³£Ê¹ÓÃ.
ºÃÁË.Á˽âÁËÔÀíÖ®ºó,ÎÒÃÇÀ´ÊµÕ½Ò»ÏÂÈçºÎʹÓÃMySQLÌáÉýȨÏÞ.
ÔÚÕâÀïÎÒÃÇÒѾͨ¹ý¸÷ʽ¸÷ÑùµÄ©¶´È¡µÃÁËÒ»¸ö·þÎñÆ÷µÄWebShell,ÎÒÕâÀïÑÝʾµÄÊÇangelµÄphpspy,ÒòΪPHPĬÈÏÓÐÁ¬½ÓMySQLµÄº¯Êý,¶øASPÕâЩÐèҪʹÓø½¼ÓµÄ×é¼þÀ´½øÐÐÁ¬½Ó,±¾Éí²»¾ß±¸Ìõ¼þµÄ.
Ò»°ãÀ´Ëµ,ÔÚWinϵͳÏÂÃæ,ºÜ¶àÈí¼þ¶¼»áÔÚϵͳĿ¼Ï´´½¨Ò»¸ö½Ðmy.iniµÄÎļþ,ÆäÖаüº¬Á˺ÜÃô¸ÐµÄMySQLÐÅÏ¢.¶øÈç¹ûÎÒÃǹ¥¿ËµÄÖ÷»úûÓÐ·Ç ³£ºÃµÄȨÏÞÉèÖõĻ°,ÎÒÃDZ¾Éí¾Í¾ßÓжÔ%windir%Ŀ¼µÄä¯ÀÀȨÏÞ,ËùÒÔ¿ÉÒԷdz£ÈÝÒ׵ĶÁÈ¡ÆäÖеÄÐÅÏ¢.¶øÇҷdz£¶àµÄ¹ÜÀíԱͨ³£Êǽ«rootÕÊ»§Ó
Ïà¹ØÎĵµ£º
MYSQL°²×°
//½âѹ±àÒë°²×°
# tar xzvf mysql-5.0.27.tar.gz
# cd mysql-5.0.27
# ./configure -prefix=/home/redadmin/mysql
# make
# make install
# cd /home/redadmin/mysql/
# cp share/mysql/my-medium.cnf ./
# mv my-medium.cnf my.cnf
// my.confÎļþÐÞ¸Ä
# vi my.cnf
ÐÞ¸ÄÇ°£º
port &nb ......
Éý»ªÌṩÖÕÉíÃâ·ÑASP+access PHP+mysqlÐéÄâÖ÷»ú
Ò»£ºÉý»ªÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾,ÓëÉý»ªÍ¬ÔÚÕ¾³¤ÖÕÉíÃâ·Ñ¿Õ¼ä·ö³Ö¼Æ»®.
1¡¢×ð¾´µÄÓû§ÄúºÃ,Ò²ÐíÄú»¹ÔÚΪÿÄêÒ»½»µÄ¿Õ¼ä·ÑÓ÷¢³î,Ò²ÐíÄúÏë»ñµÃÒ»¸ö¸üÓÅÖʵĿռäÈ´²»ÏëͶÈëÌ«¶à,´ÓÏÖÔÚÆð ÕâЩÎÊÌ⽫ÓÈжø½â→Éý»ªÍøÂç←ÓëÉý»ªÍ¬ÔÚÕ¾³¤·ö³Ö¼Æ»®È«ÃæÆô¶¯¡£
2¡¢Ã»ÓÐ×¢²á¹«Ë¾ ......
1.CREATE USER
CREATE USER user [IDENTIFIED BY [PASSWORD] 'password']
[, user [IDENTIFIED BY [PASSWORD] 'password']] ...
CREATE USERÓÃÓÚ´´½¨ÐµÄMySQLÕË»§¡£ÒªÊ¹ÓÃCREATE USER£¬Äú±ØÐëÓµÓÐmysqlÊý¾Ý¿âµÄÈ«¾ÖCREATE USERȨÏÞ£¬»òÓµÓÐINSERTȨÏÞ¡£¶ÔÓÚÿ¸öÕË»§£¬CREATE USER»áÔÚûÓÐȨÏÞµÄmysq ......
´úÂëÈçÏ£º
1 String command = " cmd /c C:/Program Files/MySQL/MySQL Server 5.0/bin>mysqldump -h localhost -u root -p aijia > E:/aijia.dmp " ;
2 try {
3 Process process& ......
°²×°MySQL
sudo apt-get install mysql-server mysql-admin mysql-navigator mysql-query-browser
Õâ¸öÓ¦¸ÃºÜ¼òµ¥ÁË£¬¶øÇÒÎÒ¾õµÃ´ó¼ÒÔÚ°²×°·½ÃæҲûʲô̫´óÎÊÌ⣬ËùÒÔÒ²¾Í²»¶à˵ÁË£¬ÏÂÃæÎÒÃÇÀ´½²½²ÅäÖá£
ÅäÖÃMySQL
×¢Ò⣬ÔÚUbuntuÏÂMySQLȱʡÊÇÖ»ÔÊÐí±¾µØ·ÃÎʵģ¬Èç¹ûÄãÒªÆäËû»úÆ÷Ò²Äܹ»·ÃÎʵĻ°£¬ÄÇôÐèÒª¸Ä±ä/etc/m ......