MYSQL³õѧÕßʹÓÃÖ¸ÄÏ
Ò»¡¢Á¬½ÓMYSQL¡£
¸ñʽ£º mysql –hÖ÷»úµØÖ· –uÓû§Ãû £pÓû§ÃÜÂë
1¡¢Àý1£ºÁ¬½Óµ½±¾»úÉϵÄMYSQL¡£
Ê×ÏÈÔÚ´ò¿ªDOS´°¿Ú£¬È»ºó½øÈëĿ¼ mysqlbin£¬ÔÙ¼üÈëÃüÁîmysql -uroot -p£¬»Ø³µºóÌáʾÄãÊäÃÜÂ룬Èç¹û¸Õ°²×°ºÃMYSQL£¬³¬¼¶Óû§rootÊÇûÓÐÃÜÂëµÄ£¬¹ÊÖ±½Ó»Ø³µ¼´¿É½øÈëµ½MYSQLÖÐÁË£¬MYSQLµÄÌáʾ·ûÊÇ£ºmysql>
2¡¢Àý2£ºÁ¬½Óµ½Ô¶³ÌÖ÷»úÉϵÄMYSQL¡£¼ÙÉèÔ¶³ÌÖ÷»úµÄIPΪ£º110.110.110.110£¬Óû§ÃûΪroot,ÃÜÂëΪabcd123¡£Ôò¼üÈëÒÔÏÂÃüÁ
mysql -h110.110.110.110 -uroot -pabcd123
£¨×¢:uÓëroot¿ÉÒÔ²»Óüӿոñ£¬ÆäËüÒ²Ò»Ñù£©
3¡¢Í˳öMYSQLÃüÁ exit £¨»Ø³µ£©
¶þ¡¢ÐÞ¸ÄÃÜÂë¡£
¸ñʽ£ºmysqladmin -uÓû§Ãû -p¾ÉÃÜÂë password ÐÂÃÜÂë
1¡¢Àý1£º¸øroot¼Ó¸öÃÜÂëab12¡£Ê×ÏÈÔÚDOSϽøÈëĿ¼mysqlbin£¬È»ºó¼üÈëÒÔÏÂÃüÁî
mysqladmin -uroot -password ab12
×¢£ºÒòΪ¿ªÊ¼Ê±rootûÓÐÃÜÂ룬ËùÒÔ-p¾ÉÃÜÂëÒ»Ïî¾Í¿ÉÒÔÊ¡ÂÔÁË¡£
2¡¢Àý2£ºÔÙ½«rootµÄÃÜÂë¸ÄΪdjg345¡£
mysqladmin -uroot -pab12 password djg345
Èý¡¢Ôö¼ÓÐÂÓû§¡££¨×¢Ò⣺ºÍÉÏÃæ²»Í¬£¬ÏÂÃæµÄÒòΪÊÇMYSQL»·¾³ÖеÄÃüÁËùÒÔºóÃæ¶¼´øÒ»¸ö·ÖºÅ×÷ΪÃüÁî½áÊø·û£©
¸ñʽ£ºgrant select on Êý¾Ý¿â.* to Óû§Ãû@µÇ¼Ö÷»ú identified by "ÃÜÂë"
Àý1¡¢Ôö¼ÓÒ»¸öÓû§test1ÃÜÂëΪabc£¬ÈÃËû¿ÉÒÔÔÚÈκÎÖ÷»úÉϵǼ£¬²¢¶ÔËùÓÐÊý¾Ý¿âÓвéѯ¡¢²åÈë¡¢Ð޸ġ¢É¾³ýµÄȨÏÞ¡£Ê×ÏÈÓÃÒÔrootÓû§Á¬ÈëMYSQL£¬È»ºó¼üÈëÒÔÏÂÃüÁ
grant select,insert,update,delete on *.* to test1@"%" Identified by "abc";
µ«Àý1Ôö¼ÓµÄÓû§ÊÇÊ®·ÖΣÏյģ¬ÄãÏëÈçij¸öÈËÖªµÀtest1µÄÃÜÂ룬ÄÇôËû¾Í¿ÉÒÔÔÚinternetÉϵÄÈκÎһ̨µçÄÔÉϵǼÄãµÄmysqlÊý¾Ý¿â²¢¶ÔÄãµÄÊý¾Ý¿ÉÒÔΪËùÓûΪÁË£¬½â¾ö°ì·¨¼ûÀý2¡£
Àý2¡¢Ôö¼ÓÒ»¸öÓû§test2ÃÜÂëΪabc,ÈÃËûÖ»¿ÉÒÔÔÚlocalhostÉϵǼ£¬²¢¿ÉÒÔ¶ÔÊý¾Ý¿âmydb½øÐвéѯ¡¢²åÈë¡¢Ð޸ġ¢É¾³ýµÄ²Ù×÷£¨localhostÖ¸±¾µØÖ÷»ú£¬¼´MYSQLÊý¾Ý¿âËùÔÚµÄÄÇ̨Ö÷»ú£©£¬ÕâÑùÓû§¼´Ê¹ÓÃÖªµÀtest2µÄÃÜÂ룬ËûÒ²ÎÞ·¨´ÓinternetÉÏÖ±½Ó·ÃÎÊÊý¾Ý¿â£¬Ö»ÄÜͨ¹ýMYSQLÖ÷»úÉϵÄwebÒ³À´·ÃÎÊÁË¡£
grant select,insert,update,delete on mydb.* to test2@localhost identified by "abc";
Èç¹ûÄã²»Ïëtest2ÓÐÃÜÂ룬¿ÉÒÔÔÙ´òÒ»¸öÃüÁÃÜÂëÏûµô¡£
grant select,insert,update,delete on mydb.* to test2@localhost identified by "";
Ó
Ïà¹ØÎĵµ£º
mysql> GRANT SELECT,INSERT,UPDATE,DELETE,CREATE,DROP
-> ON bankaccount.*
-> TO 'custom'@'localhost'
-> IDENTIFIED BY 'password';
mysql> GRANT SELECT,INS ......
Linux + Apache2.0 + Mysql + PHP + phpBB3.0
1.°²°ü£º
Apache2.0
#tar -zxf httpd-***.tar.gz -C /usr/local/src/
#cd /usr/local/src/httpd-***
  ......
·ÀÖ¹×¢ÈëµÄ¼¸ÖÖ°ì·¨
ÆäʵÔÀ´¾ÍÊÇÎÒÃÇÐèÒª¹ýÂËһЩÎÒÃdz£¼ûµÄ¹Ø¼ü×ֺͷûºÏÈ磺
Select£¬insert£¬update£¬delete£¬and£¬*£¬µÈµÈ
function inject_check($sql_str) {
return eregi('select|insert|update|delete|\'|\/\*|\*|\.\.\/|\.\/|union|into|load_file
|outfile', $sql_str); & ......
MysqlÂÒÂë²úÉúµÄÔÒò£º
²úÉú´ËÀàÎÊÌâµÄ×î¿ÉÄÜÊÇÄãµÄÊý¾Ý¿âÔÚ°²×°Ê±Ã»ÓÐÑ¡¶Ô×Ö·û¼¯£¬Õâ¸öÊ®·ÖÖØÒª.
Äã¿ÉÒÔͨ¹ýÈçϵķ½Ê½À´²é¿´£º´ò¿ªMysql´°¿Ú£¬ÔÚ´°¿ÚµÄ×î×óÉϽǵã»÷Êó±êÓÒ¼ü£¬Ñ¡ÔñÊôÐÔ£¬¾Í¿ÉÒÔ¿´µ½ÄãĬÈϵÄ×Ö·û±àÂëÁË£¨ÈçÏÂͼ£©£º
......