Ëæ×żÆËã»úµÄÆÕ¼°ÒÔ¼°ÍøÂçµÄ·¢Õ¹£¬Êý¾Ý¿âÒѾ²»ÔÙ½ö½öÊÇÄÇЩ³ÌÐòÔ±ËùרÓеϰÌâ¡£¶øOracleÊý¾Ý¿â¸üÊÇÆ¾½èÆäÐÔÄÜ׿Խ£¬²Ù×÷·½±ãÁé»îµÄÌØµã£¬ÔÚÊý¾Ý¿âµÄÊг¡ÖÐÒѾռ¾ÝÁËһϯ֮µØ¡£µ«ÊÇͬÑùËæ×ÅÍøÂç¼¼ÊõµÄ²»¶Ï½ø²½£¬Êý¾ÝÐÅÏ¢µÄ²»¶ÏÔö¼Ó£¬Êý¾Ý°²È«ÒѾ²»ÔÙÊÇÒÔǰµÄ“ÀÏÉú³¤Ì¸”£¬Ò²¸ü²»ÊÇÒÔǰÊé±¾ÉÏÄÇЩ“¿ÉÍû²»¿É¼°”µÄÌõÌõ¿ò¿ò¡£
¡¡¡¡»òÐíºÜ¾ÃÒÔǰ£¬´ó¼Ò¶¼¾õµÃOracleÊý¾Ý¿âµÄ°²È«²¢²»´æÔÚÒþ»¼£¬ÒòΪOracle¹«Ë¾ÔÚÈ¥Äê11Ô·ݿªÊ¼´ÙÏúÆäÊý¾Ý¿âÈí¼þʱÌá³öµÄ¿ÚºÅÊǓֻÓÐOracle9iÄܹ»×öµ½¾ø¶Ô°²È«”¡£µ«ÊDz»¹ÜËüÕâô˵ÊÇΪÁË´ÙÏú£¬»¹ÊÇΪÁËÀ©´óÖªÃû¶È£¬×ÜÖ®°éÈ¥Äê12 Ô·ݣ¬Ó¢¹úµÄ°²È«×¨¼Ò David Litchfield ·¢ÏÖµÄ9iAS ÖдæÔڵijÌÐò´íÎóµ¼ÖµĻº³åÒç³ö©¶´ÒÔ¼°ºóÀ´£¬PenTest Limited ºÍ eEye Digital Security ¸÷×ÔÌá³öÁËÒ»¸öСµÄ©¶´£¬ËùÓÐʹÓÃOracle¹«Ë¾²úÆ·µÄÈ˶¼²»ÓɵؽôÕÅÁËÔ±¾ËɳڵĴóÄÔ--Õâ¸ö¶ÔÓÚÓû§À´Ëµ£¬±Ï¾¹¹ØÏµµ½ÁË×Ô¼ºµÄ“Éí¼ÒÐÔÃü”¡£
¡¡¡¡ÏÂÃæ±ÊÕß½«´ø×Å´ó¼Ò×ß½øOracleÊý¾Ý°²È«µÄÊÀ½ç¡£ÓÉÓÚ±ÊÕßˮƽÓÐÏÞ£¬ËùÒÔ²»×ãÖ®´¦ÔÚËùÄÑÃ⣬Íû´ó¼Ò²»Áߴͽ̡£
¡¡¡¡(Ò»)OracleÊý¾Ý¿âµÄһЩ»ù±¾³£Ê¶
¡¡¡¡ÕâÀï½ö½öÊÇΪÁËÒÔºóµÄ°²È«µì¶ ......
¡¡·ÏòÃÜÂëÎļþÖÐÔö¼Ó¡¢É¾³ýÓû§:
¡¡¡¡µ±³õʼ»¯²ÎÊýREMOTE_LOGIN_PASSWORDFILEÉèÖÃΪEXCLUSIVEʱ£¬ÏµÍ³ÔÊÐí³ýINTERNAL/SYSÒÔÍâµÄÆäËûÓû§ÒÔ¹ÜÀíÔ±Éí·Ý´ÓÔ¶¶Ë»ò±¾»úµÇ¼µ½OracleÊý¾Ý¿âϵͳ£¬Ö´ÐÐÊý¾Ý¿â¹ÜÀí¹¤×÷;ÕâЩÓû§Ãû±ØÐë´æÔÚÓÚÃÜÂëÎļþÖУ¬ÏµÍ³²ÅÄÜʶ±ðËûÃÇ¡£ÓÉÓÚ²»¹ÜÊÇÔÚ´´½¨Êý¾Ý¿âʵÀýʱ×Ô¶¯´´½¨µÄÃÜÂëÎļþ£¬»¹ÊÇʹÓù¤¾ßORAPWD.EXEÊÖ¹¤´´½¨µÄÃÜÂëÎļþ£¬¶¼Ö»°üº¬INTERNAL/SYSÓû§µÄÐÅÏ¢;Ϊ´Ë£¬ÔÚʵ¼Ê²Ù×÷ÖУ¬¿ÉÄÜÐèÒªÏòÃÜÂëÎļþÌí¼Ó»òɾ³ýÆäËûÓû§Õʺš£
¡¡¡¡ÓÉÓÚ½ö±»ÊÚÓèSYSOPER/SYSDBAϵͳȨÏÞµÄÓû§²Å´æÔÚÓÚÃÜÂëÎļþÖУ¬ËùÒÔµ±ÏòijһÓû§ÊÚÓè»òÊÕ»ØSYSOPER/SYSDBAϵͳȨÏÞʱ£¬ËûÃǵÄÕʺÅÒ²½«ÏàÓ¦µØ±»¼ÓÈëµ½ÃÜÂëÎļþ»ò´ÓÃÜÂëÎļþÖÐɾ³ý¡£ÓÉ´Ë£¬ÏòÃÜÂëÎļþÖÐÔö¼Ó»òɾ³ýijһÓû§£¬Êµ¼ÊÉÏÒ²¾ÍÊǶÔijһÓû§ÊÚÓè»òÊÕ»ØSYSOPER/SYSDBAϵͳȨÏÞ¡£
¡¡¡¡Òª½øÐдËÏîÊÚȨ²Ù×÷£¬ÐèʹÓÃSYSDBAȨÏÞ(»òINTERNALÕʺÅ)Á¬ÈëÊý¾Ý¿â£¬ÇÒ³õʼ»¯²ÎÊýREMOTE_LOGIN_PASSWORDFILEµÄÉèÖñØÐëΪEXCLUSIVE¡£¾ßÌå²Ù×÷²½ÖèÈçÏÂ:
¡¡¡¡´´½¨ÏàÓ¦µÄÃÜÂëÎļþ;
¡¡¡¡ÉèÖóõʼ»¯²ÎÊýREMOTE_LOGIN_PASSWORDFILE=EXCLUSIVE;
¡¡¡¡Ê¹ÓÃSYSDBAȨÏ޵Ǽ: CONNECT¡¡SYS/internal_user_passsword¡¡AS¡¡S ......
¸ÅÊö
ÔÚoracle°²×°Ä¿Â¼$HOME/network/adminÏÂ,£¬¾³£¿´µ½sqlnet.ora tnsnames.ora listener.oraÕâÈý¸öÎļþ£¬³ýÁËtnsnames.ora£¬ÆäËûÁ½¸öÎļþÏêϸµÄÓÃ;ºÜ¶àÈ˶¼²»Ì«Á˽⡣
sqlnet.ora ÓÃÔÚoracle client¶Ë£¬ÓÃÓÚÅäÖÃÁ¬½Ó·þÎñ¶ËoracleµÄÏà¹Ø²ÎÊý.
tnsnames.ora ÓÃÔÚoracle client¶Ë£¬Óû§ÅäÖÃÁ¬½ÓÊý¾Ý¿âµÄ±ðÃû²ÎÊý,¾ÍÏñϵͳÖеÄhostsÎļþÒ»Ñù¡£listener.ora ÓÃÔÚoracle server¶Ë£¬ÅäÖÃoracle·þÎñ¶Ë³ÌÐòµÄ¼àÌý°ì·¨£¬±ÈÈçÏÞÖÆÄ³Ð©ipµÈ²ÎÊý¡£
ÔÚ°²×°Ä¿Â¼$HOME/network/admin/samplesÏ£¬»á¿´µ½ÈçÉÏÉϸöÎļþµÄʾÀýÎļþ£¬ÀïÃæ»áÓÐÏà¹Ø²ÎÊýµÄ˵Ã÷ºÍÓ÷¨£¬Èç¹ûÓöµ½Ê²Ã´ÎÊÌ⣬´ó¼Ò¿ÉÒÔ¶ÔÕÕÕâЩʾÀýÎļþÖÐÏà¹Ø²ÎÊýµÄ˵Ã÷½øÐнâ¾ö¡£
Èç¹ûÁ¬½ÓÊý¾Ý¿â³öÁËʲôÎÊÌ⣬ÔÚ±£Ö¤ÍøÂç³öÕý³££¬Ã»ÓзÀ»ðǽ¸ÉÈŵÄÇé¿öÏ£¬²éÕÒÎÊÌâµÄ²½ÖèÊÇ:
1)ÔÚ¿Í»§¶Ë˳Ðò¼ì²ésqlnet.ora£¬tnsnames.oraÊÇÓÐÎÊÌâ¡£
2)ÔÚ·þÎñÆ÷¶Ë¼ì²élistener.oraÅäÖ㬲¢ÇÒ±£Ö¤¼àÌý³ÌÐòÆô¶¯£¬Êý¾Ý¿â·þÎñ¼ÓÔØ¡£
ÈÏʶsqlnet.ora
ÏÂÃæÖ»½²Êö¼¸¸ö³£ÓòÎÊýÅäÖã¬ÏêϸµÄ×ÊÁÏ£¬´ó¼Ò¿ÉÒԲ鿴ʾÀýsqlnet.oraµÃµ½¡£
sqlnet.ora¿ÉÒÔɾ³ý£¬ÕâÑùÔÚoracle¿Í»§¶ËÁ¬½ÓÊý¾Ý¿âµÄʱºò£¬Ä¬ÈϲÉÓÃtnsnames.oraÖеÄÅäÖá£
1).NAMES.DEFAULT_DOMAI ......
ǰ̨HTML´úÂë:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>ÎÞ±êÌâÒ³</title>
<style type="text/css">
a { text-decoration:none;}
</style>
<script type="text/javascript">
var xmlHttp;
function CreateXmlHttp()
{
xmlHttp=new ActiveXObject("Microsoft.XMLHTTP");
}
function StartRequest(index)
{
// alert("1");
var url="repeater.aspx?index="+index+"&key="+escape(document.getElementById("tip").value);
//alert(url);
&n ......
¿Í»§¶ËString.php,·þÎñÆ÷¶ËString_check.php£¬ºÜ¼òµ¥µÄʵÏÖ¡£
¿Í»§¶Ë´úÂ룺
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>ÎÞ±êÌâÎĵµ</title>
</head>
<script language="javascript">
var xmlHttp;
function createXMLHttpRequest(){
if(window.ActiveXObject){
xmlHttp = new ActiveXObject("microsoft.XMLHTTP");
}
else if(window.XMLHttpRequest){
xmlHttp = new XMLHttpRequest();
}
}
function sendRequest(){
createXMLHttpRequest();
var name = document.getElementById("name").value;
url = "String_check.php?page="+name;
xmlHttp.onreadystatechange = callback;
xmlHttp.open('GET',url,true);
xmlHttp.send(null);
}
function callbac ......
ÀûÓÃAJAX¶¯Ì¬»ñÈ¡µ±Ç°Ê±¼ä£¬¿Í»§¶Ëtime.php,·þÎñÆ÷¶Ëtime_check.php
¿Í»§¶Ë´úÂ룺
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>¶¯Ì¬ÏÔʾʱ¼ä</title>
</head>
<script language="javascript">
var xmlHttp;
function createXMLHttpRequest(){
if(window.ActiveXObject){
xmlHttp = new ActiveXObject("microsoft.XMLHTTP");
}
else if(window.XMLHttpRequest){
xmlHttp = new XMLHttpRequest();
}
else{
alert("´´½¨ÇëÇóʧ°Ü");
}
}
function sendRequest(){
createXMLHttpRequest();
url = "time_check.php";
xmlHttp.onreadystatechange = callback;
xmlHttp.open('GET',url,true);
xmlHttp.send(null);
}
function callback(){
if(xmlHttp.rea ......