MySQL·À×¢Èë
·ÀÖ¹×¢ÈëµÄ¼¸ÖÖ°ì·¨
ÆäʵÔÀ´¾ÍÊÇÎÒÃÇÐèÒª¹ýÂËһЩÎÒÃdz£¼ûµÄ¹Ø¼ü×ֺͷûºÏÈ磺
Select£¬insert£¬update£¬delete£¬and£¬*£¬µÈµÈ
function inject_check($sql_str) {
return eregi('select|insert|update|delete|\'|\/\*|\*|\.\.\/|\.\/|union|into|load_file
|outfile', $sql_str);
}
»òÕßÊÇͨ¹ýϵͳº¯Êý¼äµÄ¹ýÂËÌØÊâ·ûºÅ
Addslashes£¨ÐèÒª±»¹ýÂ˵ÄÄÚÈÝ£©
Ïà¹ØÎĵµ£º
µ¼³ö
select field1,field2,field3 from tablename into outfile '/home/output1.csv' fields terminated by ','optionally enclosed by ''lines terminated by '\n';
µ¼Èë
load data local infile '/home/output1.csv' into table tablename fields terminated by ','lines terminated by '\n'(field1,f ......
mysql> GRANT SELECT,INSERT,UPDATE,DELETE,CREATE,DROP
-> ON bankaccount.*
-> TO 'custom'@'localhost'
-> IDENTIFIED BY 'password';
mysql> GRANT SELECT,INS ......
ÔÚÏò´ó¼ÒÏêϸ½éÉÜLinux mysql֮ǰ£¬Ê×ÏÈÈôó¼ÒÁ˽âÏÂLinux mysql£¬È»ºóÈ«Ãæ½éÉÜLinux mysql£¬Ï£Íû¶Ô´ó¼ÒÓÐÓá£
1. Linux mysql°²×°£º
$ yum install mysql-server
2. Linux mysqlÐÞ¸ÄrootÃÜÂ룺
$ mysqladmin -u root password
your_new_passwd
3. Æô¶¯Linux mysql·þÎñ
$ /etc/init.d/mysqld start
4. Ìí¼ÓΪϵͳ· ......
È¡µÃÎÄÕ¹ؼü×ÖΪkeywords
±ínewsµÄ¹Ø¼ü×Ö×Ö¶ÎΪkeyword
keywords=keywords.replace(',','|');
String sql="SELECT * from news WHERE keyword REGEXP '"+keywords+"' ORDER BY id ";
ÓÉÓÚijЩÔÒò£¬ÓÐʱºòÎÒÃÇûÓа´ÕÕ·¶Ê½µÄÉè¼Æ×¼Ôò¶ø°ÑһЩÊôÐԷŵ½Í¬Ò»¸ö×Ö·û´®×Ö¶ÎÖС£±ÈÈç¸öÈËÐËȤ£¬ÓÐʱºòÎÒÃÇÉè¼Æ±íΪ
cr ......
ʹÓÃwhileÑ»·Óï¾äÉú³É²âÊÔÊý¾Ý£º
ÏÂÃæµÄ·½·¨ÊÇͨ¹ý´´½¨Ò»¸ö´æ´¢¹ý³Ì£¬È»ºóÔÙµ÷ÓÃÕâ¸ö´æ´¢¹ý³ÌÀ´ÊµÏֵ쬴ÓÍøÉÏÕÒÁ˺ܶ෽·¨£¬µ«¶¼Ã»Óгɹ¦¡£
delimiter // /*¶¨ÒåÃüÁî½áÊø·ûĬÈÏΪ ; */
create procedure genUsers()
begin
declare i int default 0;
while i < 40 do
insert into users(userID,userName, ......