MysqlÊý¾ÝÌáÈ¡Æ÷
¼¸¸öÔÂǰ£¬ÊÜһλÀÏʦµÄίÍУ¬Òª°ïËû×öÒ»¸ö¹ØÏµÊý¾Ý¿âģʽÐÅÏ¢ÌáÈ¡µÄСÏîÄ¿£¬Ö÷ÒªµÄ¹¦ÄÜʵÏÖ¾ÍÊǽ«¹ØÏµÊý¾Ý¿âµÄ±í½á¹¹ºÍ×ֶεÄÐÅϢͨ¹ý±í¸ñµÄÐÎʽչʾ³öÀ´¡£ÎÒͨ¹ý´ÓÍøÉÏËѼ¯×ÊÁÏÒÔ¼°·Êé²éÕÒ£¬ÏÈʵÏÖÁËÒ»¸ömysqlµÄÊý¾ÝÌáÈ¡Æ÷¡£Ïȸø´ó¼Ò·ÖÏíһϡ£ÉÔºóµÄ¼¸ÌìÄÚ»á°ÑÁíÒ»¸ömysql¹ØÏµÄ£Ê½ÌáÈ¡Æ÷¸ø´ó¼Ò·ÖÏí¡£
Ò»£®¹¦ÄܽéÉÜ£º
±¾³ÌÐòÖ÷ÒªÓÃÀ´ÊµÏÖ¶ÔmysqlÊý¾Ý¿âÀïµÄ±íÊý¾ÝÐÅÏ¢½øÐÐÌáÈ¡£¬¿ÉÒÔ·½Ãæ¿ì½ÝµØ²é¿´¸÷¸öÊý¾Ý¿âºÍ²»Í¬µÄģʽºÍ±íÖ®¼äµÄÊý¾ÝÐÅÏ¢¡£
¶þ£®ÊµÏÖ¹ý³Ì£º
1..²ÉÓÃNative Protocol Pure-javaÇý¶¯³ÌÐò, ¿ÉÒÔͨ¹ýʹÓÃÌØ¶¨ÓÚ¹©Ó¦É̵ÄÍøÂçÐÒéÀ´Ö±½ÓÓëÊý¾Ý¿â½øÐн»»¥,µ¼ÈëÒ»¸öÌṩ´ËÇý¶¯³ÌÐòµÄjar°ü£¬²¢ÔÚÖ÷º¯ÊýÖÐ×¢²á´ËÇý¶¯¡£Ö÷Òª´úÂëÈçÏ£º
2.ÔËÐгÌÐò£¬ÏÔʾÈçϵÇÂ¼Ò³Ãæ£¬ÔÚuseridÀ¸ÖÐÊäÈëmysqlÊý¾Ý¿âµÄÓû§Ãûroot£¬ÔÚpasswordÀ¸ÀïÊäÈëmysqlÊý¾Ý¿âÃÜÂë123456£¬ÔÚurlÀ¸ÖÐÊäÈëÁ¬½ÓmysqlÊý¾Ý¿âµÄurl£¬ÀýÈ磺jdbc:mysql://127.0.0.1:3306/test¡£Ö®ºó£¬Èç¹ûµã»÷È¡Ïû°´Å¥£¬ÔòÍ˳öϵͳ£»µã»÷µÇ¼ϵͳ£¬Ôò½øÐÐÅжϣ¬ÔÚÊäÈëµÄÓû§Ãû£¬ÃÜÂë»òURLÓдíÎóµÄʱºò£¬µ¯³ö´íÎóÏûÏ¢Ìáʾ¿ò½øÐÐÌáʾ£¬Ö»ÓÐÕýÈ·ÊäÈëºó²ÅÄܽøÈëÊý¾ÝÏÔÊ¾Ò³Ãæ¡£
µã»÷È·¶¨°´Å¥ºó£¬Çå¿ÕÒÔǰ´íÎóÐÅÏ¢£¬¹â±ê¶¨Î»ÔÚuseridÁС£Ö÷Òª´úÂëÈçÏ£º
3.³É¹¦µÇ¼ºó£¬ÐÅÏ¢³õʼ»¯Ò³ÃæÊÇĬÈÏÑ¡ÔñµÇ¼µÄÊý¾Ý¿âÃû³Æ£¬¼ÙÈçURLÖÐÓõ½µÄÊÇTestÊý¾Ý¿âµÇ¼£¬ÔòĬÈÏÑ¡ÔñtestÊý¾Ý¿â£¬SchemaºÍTable¶¼ÊÇ´Ë¿âÖеĵÚÒ»ÌõÊý¾Ý¡£Èç¹ûΪ¿Õ£¬ÏÂÀ¿ò¿Ø¼þÏÔʾΪ²»¿ÉÓÃ״̬¡£
Èç¹ûURLÎı¾¿òÖиÄΪjdbc:mysql://127.0.0.1:3306/onlinexam£¬Ôòµã»÷µÇ¼ºóµ¯³öµÄÖ÷Ò³ÃæÎª
Õû¸öÒ³ÃæÓÉÈý²¿·Ö×é³É£¬²ÉÓÃBorderLayout²¼¾Ö¹ÜÀíÆ÷£¬±±ÃæÊDzéѯµÄPanel£¬ÖмäÊÇÊý¾Ý¿â±íÐÅÏ¢µÄÏÔʾPanel£¬ÄÏÃæÊÇÍ˳öÃæ°åµÄPanel¡£
ÔÚ²éѯPanelÖУ¬Í¨¹ýcatalogÏÂÀ¿òÑ¡Ôñ²»Í¬µÄÊý¾Ý¿â£¬×Ô¶¯³õʼ»¯schemaÓû§ºÍtable±í£¬Èç¹ûΪ¿Õ£¬Ôò²»ÏÔʾÊý¾Ý£¬ÇÒÏÂÀ¿ò²»¿ÉÓá£CatalogÏÂÀ¿ò£¬SchemaÏÂÀ¿ò£¬TableÏÂÀ¿ò¼àÌýʼþ³ÌÐòΪ£º
·Ö±ðÓÃÈý¸öº¯ÊýÀ´ÊµÏÖ¶ÔÈý¸öÏÂÀ¿òÐÅÏ¢µÄ×°ÔØ£¬È»ºóÓÃÒ»¸öº¯ÊýÀ´ÊµÏÖ¶ÔÖмäPanelµÄ±íÊý¾ÝÐÅÏ¢µÄ²éѯ£º
ÏÂÃæÕ¹Ê¾ÊµÏÖµÄÇé¿ö.
¶ø×îºó£¬ÓÃÒ»¸öÄÚ²¿ÀàÀ´ÊµÏÖ¶Ô±í¸ñµÄ¶¯Ì¬Ìî³ä£¬Í¨¹ý¼Ì³ÐAbs
Ïà¹ØÎĵµ£º
±¸·ÝMySQLÊý¾Ý¿âµÄÃüÁî
mysqldump -hhostname -uusername -ppassword databasename > backupfile.sql
±¸·ÝMySQLÊý¾Ý¿âΪ´øÉ¾³ý±íµÄ¸ñʽ
±¸·ÝMySQLÊý¾Ý¿âΪ´øÉ¾³ý±íµÄ¸ñʽ£¬Äܹ»Èøñ¸·Ý¸²¸ÇÒÑÓÐÊý¾Ý¿â¶ø²»ÐèÒªÊÖ¶¯É¾³ýÔÓÐÊý¾Ý¿â¡£
mysqldump -–add-drop-table -uusername -ppassword databasename > bac ......
by ZaraByte
How to do a SQL Injection for MYSQL Server 5.0+
1. Find a vulnerable add a ‘ at the end of the site example: news.php?id=1 add a ‘ at the end of the 1 and see if you get a syntax error
2. order by #–
Keep upping the # until you get an error.
3. union all select 1 ......
Èç¹ûÄãÊǸöÈü³µÊÖ²¢ÇÒ°´Ò»Ï°´Å¥¾ÍÄܹ»Á¢¼´¸ü»»ÒýÇæ¶ø²»ÐèÒª°Ñ³µ¿ªµ½³µ¿âÀïÈ¥»»£¬ÄÇ»áÊÇÔõô¸Ð¾õÄØ£¿MySQLÊý¾Ý¿âΪ¿ª·¢ÈËÔ±Ëù×öµÄ¾ÍºÃÏñÊǰ´°´Å¥»»ÒýÇæ£»ËüÈÃÄãÑ¡ÔñÊý¾Ý¿âÒýÇæ£¬²¢¸øÄãÒ»Ìõ¼òµ¥µÄ;¾¶À´Çл»Ëü¡£
MySQL µÄ×Ô´øÒýÇæ¿Ï¶¨Êǹ»ÓÃÁË£¬µ«ÊÇÔÚÓÐЩÇé¿öÏ£¬ÆäËûµÄÒýÇæ¿ÉÄÜÒª±ÈÊÖÍ·ËùÓøüÊʺÏÍê³ÉÈÎÎñ¡£Èç¹ûÔ¸Ò ......
Ò»¡¢ÉèÖÃÊý¾Ý¿â±àÂë
°²×°mysqlʱ¿ÉÑ¡Ôñ±àÂ룬Èç¹ûÒѾ°²×°¹ý£¬¿ÉÒÔ¸ü¸ÄÎļþmy.ini(´ËÎļþÔÚmysqlµÄ°²×°Ä¿Â¼ÏÂ)ÖеÄÅäÖÆÒԴﵽĿµÄ£»´ò¿ªÎļþÕÒµ½Á½´¦£º
[client]
port=3306
[mysql]
default-character-set=gb2312
# The default character set that will be used when a new
schema or table is
# created and
n ......
Ò»:°²×°
ÎÞÂÛÄãϲ»¶µÄÊÇÄÄÖÖLINUXÌ×¼þ£¬Ëü¶¼ÓпÉÄÜ´øÓÐMySQL¡£Slackware,Ret Hat,SusEºÍDebianÖж¼ÔÚËüÃǵĵ±Ç°°æ±¾Öаüº¬ÁËËü£¬Õ⽫ÌṩһÖÖ×î¼òµ¥µÄ·½Ê½À´¿ìËÙ°²×°ºÍÔËÐÐMySQL¡£Èç¹ûÄãµÄ·¢Ðа汾ÖÐûÓÐÌṩMySQLÈí¼þ°ü£¬»òÕßÄãÏëµÃµ½×îеİ汾£¬Äã¿ÉÒÔ´ÓMySQLµÄÍøÕ¾:www.mysql.comÉÏÏÂÔØ¶þ½øÖưü»òÔ ......