ÈçºÎʹÓÃMySQLÌáÉýȨÏÞ
Ç°²»¾ÃÍøÉϹ«¿ªÁËÒ»¸öMySQL FuncµÄ©¶´,½²µÄÊÇʹÓÃMySQL´´½¨Ò»¸ö×Ô¶¨ÒåµÄº¯Êý,È»ºóͨ¹ýÕâ¸öº¯ÊýÀ´¹¥»÷·þÎñÆ÷¡£×îÔç¿´µ½Ïà¹ØµÄ±¨µÀÊÇÔÚo-otikÉÏ,µ«Êǹ«²¼µÄÊÇÕë¶Ô UnixϵͳµÄExploit,²¢Çҳɹ¦ÂÊÒ²²»ÊǺܸß.¶ø½üÆÚ,¹úÄÚÓиßÊַųöÕë¶ÔWinϵͳµÄÏà¹ØÎÄÕÂ,ÓÚÊÇÎÒÂíÉÏÕÒÀ´ÓëÅóÓÑһͬÑо¿.
ÆäʵÎÒÃÇÔç¾ÍÄÜÏëµ½.µ±ÎÒÃÇÔÚ¶ÔMSSQL\OracleÊý¾Ý¿â½øÐй¥»÷µÄʱºò,µÃµ½ÁË×îÊý¾Ý¿âÖиßȨÏÞµÄÕÊ»§,ÍùÍù¶¼ÊÇÖ´ÐÐÌØÊâµÄÀ©Õ¹¹ý³Ì»òÕߺ¯ÊýÀ´ ½øÐй¥»÷µÄ¡£±ÈÈçMSSQLÓÐXp_cmdshell,Oracle¿ÉÒÔͨ¹ýMsvcrt.dllÀ´´´½¨Ò»¸öÌØÊâµÄº¯Êý.¶øÎÒÃÇȴʼÖÕûÓÐÏëµ½,×÷ΪÁ÷ÐÐ µÄÊý¾Ý¿âÈí¼þÖ®Ò»µÄMySQL,Ò²ÊÇ¿ÉÒÔ½øÐк¯ÊýµÄ´´½¨µÄ.ÓÉ´Ë¿´À´,MySQLµÄÕâ¸ö©¶´²»Ó¦³ÆΪ©¶´¶ø½ö½öÊÇÒ»¸ö¼¼Êõ¶øÒÑ.
·Ï»°Ò»¶Ñ¹ýºó,ÎÒÃÇÀ´Á˽âÒ»ÏÂÔõôÔÚMySQLÀï´´½¨Ò»¸öº¯Êý°É.Õâ±ÈÈçºÎÀûÓÃÖØÒªÐí¶à,Ö»ÒªÁ˽âÁËÔÀí,ÔËÓþÍÄܸü¼ÓÁé»î,¶øÇÒ¿ÉÒÔÓëÆäËû˼ÏëÈÚ»á¹áͨ.
MySQLÖд´½¨Ò»¸öº¯ÊýµÄÓï¾äΪ:
Create Function FunctionName Returns [String|Integer|Real] Soname ‘C:\function.dll’;
ÆäÖÐFunctionNameÖ¸µÄÊǺ¯ÊýµÄÃû³Æ,C:\Function.DLLÖ¸µÄÊǺ¯ÊýËùµ÷ÓõÄDLL,¶øº¯ÊýÃûÕýÊÇDLLÖеĺ¯ÊýÃû³Æ.²»¹ýÕâÀï ÐèÒªÎÒÃÇ×¢ÒâµÄÊÇ,Èç¹ûÎÒÃÇÐèÒªMySQL¿ÉÒÔÔÚº¯ÊýÖ®Öи½´øÒ»¸ö²ÎÊýµÄ»°,ÄÇô¾ÍÒª·ûºÏUDFÐÎʽµÄ³ÌÐò±àд¹æÔò,¾ßÌåµÄ¿ÉÒԲ鿴MySQLÊÖ²áµÄµÚ 14½Ú:¡¶ÎªMySQLÔö¼Óк¯Êý¡·.¶øÆäÖÐSTRING,INTEGET,REALÊǺ¯ÊýÖ´ÐкóËù·µ»ØµÄÖµµÄÐÎʽ.µ±È»,ÎÒÃÇ´ó¿É²»±Ø×ñÑUDFÐÎʽµÄ ±àд,ÆäʵÈç¹ûÎÒÃǵĺ¯ÊýÖÐʹÓÃÒ»¸öÎÒÃÇÒªÖ´ÐеĴúÂë,¶ø²»Ê¹ÓòÎÊý,Ò»Ñù¿ÉÒÔ´ïµ½¹¥»÷µÄЧ¹û,±ÈÈç˵System(”command.com”)µÈµÈ. ÍøÉÏÏÖÔÚÒÔ´Ë©¶´½øÐй¥»÷µÄFurQÈä³æ¾ÍÊÇÒ»¸ö²»Ê¹ÓÃUDF¸ñʽµÄÀý×Ó.µ«ÊÇ×¢Òâ,Õâ¸ö´´½¨º¯ÊýµÄÓï¾ä±ØÐëÒªÇóÎÒÃÇËùÓõÄMySQLÕÊ»§ÓжÔmysql Õâ¸öÊý¾Ý¿âµÄдȨÏÞ,·ñÔòÎÞ·¨Õý³£Ê¹ÓÃ.
ºÃÁË.Á˽âÁËÔÀíÖ®ºó,ÎÒÃÇÀ´ÊµÕ½Ò»ÏÂÈçºÎʹÓÃMySQLÌáÉýȨÏÞ.
ÔÚÕâÀïÎÒÃÇÒѾͨ¹ý¸÷ʽ¸÷ÑùµÄ©¶´È¡µÃÁËÒ»¸ö·þÎñÆ÷µÄWebShell,ÎÒÕâÀïÑÝʾµÄÊÇangelµÄphpspy,ÒòΪPHPĬÈÏÓÐÁ¬½ÓMySQLµÄº¯Êý,¶øASPÕâЩÐèҪʹÓø½¼ÓµÄ×é¼þÀ´½øÐÐÁ¬½Ó,±¾Éí²»¾ß±¸Ìõ¼þµÄ.
Ò»°ãÀ´Ëµ,ÔÚWinϵͳÏÂÃæ,ºÜ¶àÈí¼þ¶¼»áÔÚϵͳĿ¼Ï´´½¨Ò»¸ö½Ðmy.iniµÄÎļþ,ÆäÖаüº¬Á˺ÜÃô¸ÐµÄMySQLÐÅÏ¢.¶øÈç¹ûÎÒÃǹ¥¿ËµÄÖ÷»úûÓÐ·Ç ³£ºÃµÄȨÏÞÉèÖõĻ°,ÎÒÃDZ¾Éí¾Í¾ßÓжÔ%windir%Ŀ¼µÄä¯ÀÀȨÏÞ,ËùÒÔ¿ÉÒԷdz£ÈÝÒ׵ĶÁÈ¡ÆäÖеÄÐÅÏ¢.¶øÇҷdz£¶àµÄ¹ÜÀíԱͨ³£Êǽ«rootÕÊ»§Ó
Ïà¹ØÎĵµ£º
¡¡¡¡ÒÔMySQL-server-4.0.14-0.i386.rpmΪÀý£¬·ÅÔÚ/dataĿ¼ÏÂ
¡¡¡¡cd /data
¡¡¡¡rpm -ivh MySQL-server-4.0.14-0.i386.rpm
¡¡¡¡°²×°Íê³ÉºóÔÚ/usr/share/mysqlĿ¼ÖлáÓÐÒ»¸ömysqlµÄÆô¶¯½Å±¾mysql.server¼°Ê¾ÀýÅäÖÃÎļþµÈ(Èçmy-huge.cnf¡¢my-large.cnf¡¢my-medium.cnf)
¡¡¡¡¿½±´Ò»¸öʾÀýÅäÖÃÎ ......
1. ¹ØµôMysql·þÎñ
2.н¨Ò»¸öÎı¾Îļþ£¬ÄÚÈÝÈçÏ£º
UPDATE mysql.user SET Password=PASSWORD('NewPassword') WHERE User='root';
FLUSH PRIVILEGES;
×¢Ò⣺һ¶¨Òª·ÖÁ½ÐÐд£¬"NewPassword"ΪÄãµÄÐÂÃÜÂë
3. ±£´æÎļþ£¬²¢°ÑËü·ÅÔÚCÅ̸ùĿ¼Ï£¬ÎļþÃûΪ"mysql-init.txt"£ºC:\mysql-init.txt
4. ´ò¿ªcmd´°¿Ú£¬Êä ......
1¡¢µÇ½MySQL:
mysql -u root -p
2¡¢²é¿´Óû§ÐÅÏ¢
select user,host,password from mysql.user;
select user,host from mysql.user;
3¡¢ÉèÖÃÃÜÂë
set password for root@localhost=password('
ÔÚÕâÀïÌîÈërootÃÜÂë
');
4¡¢ÐÞ¸ÄÃÜÂë
·½·¨1£ºmysqladmin -u root -p password newpassword
·½·¨2£º ££mysql -u root ......
1.´´½¨±í£º
create table groupTable(dept varchar(6),phone varchar(20),amount int);
2.²åÈë²âÊÔÊý¾Ý£º
insert groupTable
select 'ÓªÒµ²¿',8001,20 union all
select 'ÓªÒµ²¿',8002,30 union all
se ......
´úÂëÈçÏ£º
1 String command = " cmd /c C:/Program Files/MySQL/MySQL Server 5.0/bin>mysqldump -h localhost -u root -p aijia > E:/aijia.dmp " ;
2 try {
3 Process process& ......