Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

MySQL´æ´¢¹ý³ÌʵÀý

9.3  MySQL´æ´¢¹ý³Ì
MySQL 5.0ÒÔºóµÄ°æ±¾¿ªÊ¼Ö§³Ö´æ´¢¹ý³Ì£¬´æ´¢¹ý³Ì¾ßÓÐÒ»ÖÂÐÔ¡¢¸ßЧÐÔ¡¢°²È«ÐÔºÍÌåϵ½á¹¹µÈÌØµã£¬±¾½Ú½«Í¨¹ý¾ßÌåµÄʵÀý½²½âPHPÊÇÈçºÎ²Ù×ÝMySQL´æ´¢¹ý³ÌµÄ¡£
ʵÀý261£º´æ´¢¹ý³ÌµÄ´´½¨
ÕâÊÇÒ»¸ö´´½¨´æ´¢¹ý³ÌµÄʵÀý
¼ÏñλÖ㺹âÅÌ\mingrisoft\09\261
ʵÀý˵Ã÷
ΪÁ˱£Ö¤Êý¾ÝµÄÍêÕûÐÔ¡¢Ò»ÖÂÐÔ£¬Ìá¸ßÓ¦ÓõÄÐÔÄÜ£¬³£²ÉÓô洢¹ý³Ì¼¼Êõ¡£MySQL 5.0֮ǰµÄ°æ±¾²¢²»Ö§³Ö´æ´¢¹ý³Ì£¬Ëæ×ÅMySQL¼¼ÊõµÄÈÕÇ÷ÍêÉÆ£¬´æ´¢¹ý³Ì½«ÔÚÒÔºóµÄÏîÄ¿Öеõ½¹ã·ºµÄÓ¦Óᣱ¾ÊµÀý½«½éÉÜÔÚMySQL 5.0ÒÔºóµÄ°æ±¾Öд´½¨´æ´¢¹ý³Ì¡£
¼¼ÊõÒªµã
Ò»¸ö´æ´¢¹ý³Ì°üÀ¨Ãû×Ö¡¢²ÎÊýÁÐ±í£¬ÒÔ¼°¿ÉÒÔ°üÀ¨ºÜ¶àSQLÓï¾äµÄSQLÓï¾ä¼¯¡£ÏÂÃæÎªÒ»¸ö´æ´¢¹ý³ÌµÄ¶¨Òå¹ý³Ì£º
create procedure proc_name (in parameter integer)
begin
declare variable varchar(20);
if parameter=1 then
set variable='MySQL';
else
set variable='PHP';
end if;
insert into tb (name) values (variable);
end;
MySQLÖд洢¹ý³ÌµÄ½¨Á¢ÒԹؼü×Öcreate procedure¿ªÊ¼£¬ºóÃæ½ô¸ú´æ´¢¹ý³ÌµÄÃû³ÆºÍ²ÎÊý¡£MySQLµÄ´æ´¢¹ý³ÌÃû³Æ²»Çø·Ö´óСд£¬ÀýÈçPROCE1()ºÍproce1()´ú±íͬһ¸ö´æ´¢¹ý³ÌÃû¡£´æ´¢¹ý³ÌÃû²»ÄÜÓëMySQLÊý¾Ý¿âÖеÄÄÚ½¨º¯ÊýÖØÃû¡£
´æ´¢¹ý³ÌµÄ²ÎÊýÒ»°ãÓÉ3²¿·Ö×é³É¡£µÚÒ»²¿·Ö¿ÉÒÔÊÇin¡¢out»òinout¡£in±íʾÏò´æ´¢¹ý³ÌÖд«Èë²ÎÊý£»out±íʾÏòÍâ´«³ö²ÎÊý£»inout±íʾ¶¨ÒåµÄ²ÎÊý¿É´«Èë´æ´¢¹ý³Ì£¬²¢¿ÉÒÔ±»´æ´¢¹ý³ÌÐ޸ĺ󴫳ö´æ´¢¹ý³Ì£¬´æ´¢¹ý³ÌĬÈÏΪ´«Èë²ÎÊý£¬ËùÒÔ²ÎÊýin¿ÉÒÔÊ¡ÂÔ¡£µÚ¶þ²¿·ÖΪ²ÎÊýÃû¡£µÚÈý²¿·ÖΪ²ÎÊýµÄÀàÐÍ£¬¸ÃÀàÐÍΪMySQLÊý¾Ý¿âÖÐËùÓпÉÓõÄ×Ö¶ÎÀàÐÍ£¬Èç¹ûÓжà¸ö²ÎÊý£¬²ÎÊýÖ®¼ä¿ÉÒÔÓöººÅ½øÐзָ
MySQL´æ´¢¹ý³ÌµÄÓï¾ä¿éÒÔbegin¿ªÊ¼£¬ÒÔend½áÊø¡£Óï¾äÌåÖпÉÒÔ°üº¬±äÁ¿µÄÉùÃ÷¡¢¿ØÖÆÓï¾ä¡¢SQL²éѯÓï¾äµÈ¡£ÓÉÓÚ´æ´¢¹ý³ÌÄÚ²¿Óï¾äÒªÒԷֺŽáÊø£¬ËùÒÔÔÚ¶¨Òå´æ´¢¹ý³ÌǰӦ½«Óï¾ä½áÊø±êÖ¾“;”¸ü¸ÄΪÆäËû×Ö·û£¬²¢ÇÒ¸Ã×Ö·ûÔÚ´æ´¢¹ý³ÌÖгöÏֵļ¸ÂÊÒ²Ó¦¸Ã½ÏµÍ£¬¿ÉÒÔÓùؼü×Ödelimiter¸ü¸Ä¡£ÀýÈ磺
mysql>delimiter //
´æ´¢¹ý³Ì´´½¨Ö®ºó£¬¿ÉÓÃÈçÏÂÓï¾ä½øÐÐɾ³ý£¬²ÎÊýproc_nameÖ¸´æ´¢¹ý³ÌÃû¡£
drop procedure proc_name
ʵÏÖ¹ý³Ì
£¨1£©MySQL´æ´¢¹ý³ÌÊÇÔÚ“ÃüÁîÌáʾ·û”Ï´´½¨µÄ£¬ËùÒÔÊ×ÏÈÓ¦¸Ã´ò¿ª“ÃüÁîÌáʾ·û”´°¿Ú¡£
£¨2£©½øÈë“ÃüÁîÌáʾ·û”´°¿Úºó£¬Ê×ÏÈÓ¦¸ÃµÇ¼MySQLÊý¾Ý¿â·þÎñÆ÷£¬ÔÚ“ÃüÁîÌáʾ·û”ÏÂÊäÈëÈçÏÂÃüÁ


Ïà¹ØÎĵµ£º

MySQL³£ÓòÙ×÷»ù±¾²Ù×÷


¹Ø¼ü×Ö: mysql³£ÓòÙ×÷»ù±¾²Ù×÷
MySQL³£ÓòÙ×÷»ù±¾²Ù×÷£¬ÒÔ϶¼ÊÇMySQL5.0ϲâÊÔͨ¹ýÊ×ÏÈ˵Ã÷Ï£¬¼ÇסÔÚÿ¸öÃüÁî½áÊøÊ±¼ÓÉÏ£»£¨·ÖºÅ£©
1.µ¼³öÕû¸öÊý¾Ý¿â
mysqldump -u Óû§Ãû -p --default-character-set=latin1 Êý¾Ý¿âÃû > µ¼³öµÄÎļþÃû(Êý¾Ý¿âĬÈϱàÂëÊÇlatin1)
mysqldump -u wcnc -p smgp_apps_wcnc > wcnc. ......

Mysql ½»²æ²éѯ

CREATE TABLE `taa` (
   `year` varchar(4) DEFAULT NULL,
   `month` varchar(2) DEFAULT NULL,
   `amount` double DEFAULT NULL
 ) ENGINE=InnoDB DEFAULT CHARSET=utf
"year","m ......

[Injection]¶ÔMYSQL 5.0·þÎñÆ÷ÒÔÉϰ汾עÈë


by ZaraByte
How to do a SQL Injection for MYSQL Server 5.0+
1. Find a vulnerable add a ‘ at the end of the site example: news.php?id=1 add a ‘ at the end of the 1 and see if you get a syntax error
2. order by #–
Keep upping the # until you get an error.
3. union all select 1 ......

¼Ç¼µã¶«Î÷£¬MSSQL£¬MySQL£¬.NETµÄMD5¼ÓÃÜ

 MSSQL:select Right(sys.fn_VarBinToHexStr(hashbytes('MD5', '123456')),32)
 MSSQL16λ:select Right(sys.fn_VarBinToHexStr(hashbytes('MD5', '123456')),16)
 MySQL:select md5('123456')
 .NET:string ½á¹û×Ö·û´®=System.Web.Security.FormsAuthentication.HashPasswordForStoringInConfigFil ......

ÔÚmysqlÊý¾Ý¿âÖÐÈÕÆÚÓëlongÐ͵Äת»¯

1¡¢ÔÚmysql Êý¾Ý¿âÖУ¬“2009-09-15 00£º00£º00”ת»¯ÎªÁÐΪ³¤ÕûÐ͵ĺ¯Êý£º
select unix_timstamp("2009-09-15 00£º00£º00")*1000,
ÕâÀïҪעÒ⣬mysqlÊý¾Ý¿âÖеij¤ÕûÐÍ£¬±ÈjavaÖеij¤ÕûÐÍÉÙÁËÃëºóÃæµÄºÁÃëÊý£¬ËùÒÔÒª³ËÒÔ1000£¬ÕâÑùÖ»Óм¸ºÁÃëÖ®²î
2¡¢ÔÚmysqlÊý¾Ý¿âÖУ¬“1252999488000”£ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ