ÈçºÎʹÓÃMySQLÌáÉýȨÏÞ
ǰ²»¾ÃÍøÉϹ«¿ªÁËÒ»¸öMySQL FuncµÄ©¶´,½²µÄÊÇʹÓÃMySQL´´½¨Ò»¸ö×Ô¶¨ÒåµÄº¯Êý,È»ºóͨ¹ýÕâ¸öº¯ÊýÀ´¹¥»÷·þÎñÆ÷¡£×îÔç¿´µ½Ïà¹ØµÄ±¨µÀÊÇÔÚo-otikÉÏ,µ«Êǹ«²¼µÄÊÇÕë¶Ô UnixϵͳµÄExploit,²¢Çҳɹ¦ÂÊÒ²²»ÊǺܸß.¶ø½üÆÚ,¹úÄÚÓиßÊַųöÕë¶ÔWinϵͳµÄÏà¹ØÎÄÕÂ,ÓÚÊÇÎÒÂíÉÏÕÒÀ´ÓëÅóÓÑһͬÑо¿.
ÆäʵÎÒÃÇÔç¾ÍÄÜÏëµ½.µ±ÎÒÃÇÔÚ¶ÔMSSQL\OracleÊý¾Ý¿â½øÐй¥»÷µÄʱºò,µÃµ½ÁË×îÊý¾Ý¿âÖиßȨÏÞµÄÕÊ»§,ÍùÍù¶¼ÊÇÖ´ÐÐÌØÊâµÄÀ©Õ¹¹ý³Ì»òÕߺ¯ÊýÀ´ ½øÐй¥»÷µÄ¡£±ÈÈçMSSQLÓÐXp_cmdshell,Oracle¿ÉÒÔͨ¹ýMsvcrt.dllÀ´´´½¨Ò»¸öÌØÊâµÄº¯Êý.¶øÎÒÃÇȴʼÖÕûÓÐÏëµ½,×÷ΪÁ÷ÐÐ µÄÊý¾Ý¿âÈí¼þÖ®Ò»µÄMySQL,Ò²ÊÇ¿ÉÒÔ½øÐк¯ÊýµÄ´´½¨µÄ.ÓÉ´Ë¿´À´,MySQLµÄÕâ¸ö©¶´²»Ó¦³ÆÎªÂ©¶´¶ø½ö½öÊÇÒ»¸ö¼¼Êõ¶øÒÑ.
·Ï»°Ò»¶Ñ¹ýºó,ÎÒÃÇÀ´Á˽âÒ»ÏÂÔõôÔÚMySQLÀï´´½¨Ò»¸öº¯Êý°É.Õâ±ÈÈçºÎÀûÓÃÖØÒªÐí¶à,Ö»ÒªÁ˽âÁËÔÀí,ÔËÓþÍÄܸü¼ÓÁé»î,¶øÇÒ¿ÉÒÔÓëÆäËû˼ÏëÈÚ»á¹áͨ.
MySQLÖд´½¨Ò»¸öº¯ÊýµÄÓï¾äΪ:
Create Function FunctionName Returns [String|Integer|Real] Soname ‘C:\function.dll’;
ÆäÖÐFunctionNameÖ¸µÄÊǺ¯ÊýµÄÃû³Æ,C:\Function.DLLÖ¸µÄÊǺ¯ÊýËùµ÷ÓõÄDLL,¶øº¯ÊýÃûÕýÊÇDLLÖеĺ¯ÊýÃû³Æ.²»¹ýÕâÀï ÐèÒªÎÒÃÇ×¢ÒâµÄÊÇ,Èç¹ûÎÒÃÇÐèÒªMySQL¿ÉÒÔÔÚº¯ÊýÖ®Öи½´øÒ»¸ö²ÎÊýµÄ»°,ÄÇô¾ÍÒª·ûºÏUDFÐÎʽµÄ³ÌÐò±àд¹æÔò,¾ßÌåµÄ¿ÉÒԲ鿴MySQLÊÖ²áµÄµÚ 14½Ú:¡¶ÎªMySQLÔö¼Óк¯Êý¡·.¶øÆäÖÐSTRING,INTEGET,REALÊǺ¯ÊýÖ´ÐкóËù·µ»ØµÄÖµµÄÐÎʽ.µ±È»,ÎÒÃÇ´ó¿É²»±Ø×ñÑUDFÐÎʽµÄ ±àд,ÆäʵÈç¹ûÎÒÃǵĺ¯ÊýÖÐʹÓÃÒ»¸öÎÒÃÇÒªÖ´ÐеĴúÂë,¶ø²»Ê¹ÓòÎÊý,Ò»Ñù¿ÉÒÔ´ïµ½¹¥»÷µÄЧ¹û,±ÈÈç˵System(”command.com”)µÈµÈ. ÍøÉÏÏÖÔÚÒÔ´Ë©¶´½øÐй¥»÷µÄFurQÈ䳿¾ÍÊÇÒ»¸ö²»Ê¹ÓÃUDF¸ñʽµÄÀý×Ó.µ«ÊÇ×¢Òâ,Õâ¸ö´´½¨º¯ÊýµÄÓï¾ä±ØÐëÒªÇóÎÒÃÇËùÓõÄMySQLÕÊ»§ÓжÔmysql Õâ¸öÊý¾Ý¿âµÄдȨÏÞ,·ñÔòÎÞ·¨Õý³£Ê¹ÓÃ.
ºÃÁË.Á˽âÁËÔÀíÖ®ºó,ÎÒÃÇÀ´ÊµÕ½Ò»ÏÂÈçºÎʹÓÃMySQLÌáÉýȨÏÞ.
ÔÚÕâÀïÎÒÃÇÒѾͨ¹ý¸÷ʽ¸÷ÑùµÄ©¶´È¡µÃÁËÒ»¸ö·þÎñÆ÷µÄWebShell,ÎÒÕâÀïÑÝʾµÄÊÇangelµÄphpspy,ÒòΪPHPĬÈÏÓÐÁ¬½ÓMySQLµÄº¯Êý,¶øASPÕâЩÐèҪʹÓø½¼ÓµÄ×é¼þÀ´½øÐÐÁ¬½Ó,±¾Éí²»¾ß±¸Ìõ¼þµÄ.
Ò»°ãÀ´Ëµ,ÔÚWinϵͳÏÂÃæ,ºÜ¶àÈí¼þ¶¼»áÔÚϵͳĿ¼Ï´´½¨Ò»¸ö½Ðmy.iniµÄÎļþ,ÆäÖаüº¬Á˺ÜÃô¸ÐµÄMySQLÐÅÏ¢.¶øÈç¹ûÎÒÃǹ¥¿ËµÄÖ÷»úûÓÐ·Ç ³£ºÃµÄȨÏÞÉèÖõϰ,ÎÒÃDZ¾Éí¾Í¾ßÓжÔ%windir%Ŀ¼µÄä¯ÀÀȨÏÞ,ËùÒÔ¿ÉÒԷdz£ÈÝÒ׵ĶÁÈ¡ÆäÖеÄÐÅÏ¢.¶øÇҷdz£¶àµÄ¹ÜÀíԱͨ³£Êǽ«rootÕÊ»§Ó
Ïà¹ØÎĵµ£º
MYSQL°²×°
//½âѹ±àÒë°²×°
# tar xzvf mysql-5.0.27.tar.gz
# cd mysql-5.0.27
# ./configure -prefix=/home/redadmin/mysql
# make
# make install
# cd /home/redadmin/mysql/
# cp share/mysql/my-medium.cnf ./
# mv my-medium.cnf my.cnf
// my.confÎļþÐÞ¸Ä
# vi my.cnf
ÐÞ¸Äǰ£º
port &nb ......
1¡¢µÇ½MySQL:
mysql -u root -p
2¡¢²é¿´Óû§ÐÅÏ¢
select user,host,password from mysql.user;
select user,host from mysql.user;
3¡¢ÉèÖÃÃÜÂë
set password for root@localhost=password('
ÔÚÕâÀïÌîÈërootÃÜÂë
');
4¡¢ÐÞ¸ÄÃÜÂë
·½·¨1£ºmysqladmin -u root -p password newpassword
·½·¨2£º ££mysql -u root ......
Éý»ªÌṩÖÕÉíÃâ·ÑASP+access PHP+mysqlÐéÄâÖ÷»ú
Ò»£ºÉý»ªÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾,ÓëÉý»ªÍ¬ÔÚÕ¾³¤ÖÕÉíÃâ·Ñ¿Õ¼ä·ö³Ö¼Æ»®.
1¡¢×ð¾´µÄÓû§ÄúºÃ,Ò²ÐíÄú»¹ÔÚΪÿÄêÒ»½»µÄ¿Õ¼ä·ÑÓ÷¢³î,Ò²ÐíÄúÏë»ñµÃÒ»¸ö¸üÓÅÖʵĿռäÈ´²»ÏëͶÈëÌ«¶à,´ÓÏÖÔÚÆð ÕâЩÎÊÌ⽫ÓÈжø½â→Éý»ªÍøÂç←ÓëÉý»ªÍ¬ÔÚÕ¾³¤·ö³Ö¼Æ»®È«ÃæÆô¶¯¡£
2¡¢Ã»ÓÐ×¢²á¹«Ë¾ ......
1.CREATE USER
CREATE USER user [IDENTIFIED BY [PASSWORD] 'password']
[, user [IDENTIFIED BY [PASSWORD] 'password']] ...
CREATE USERÓÃÓÚ´´½¨ÐµÄMySQLÕË»§¡£ÒªÊ¹ÓÃCREATE USER£¬Äú±ØÐëÓµÓÐmysqlÊý¾Ý¿âµÄÈ«¾ÖCREATE USERȨÏÞ£¬»òÓµÓÐINSERTȨÏÞ¡£¶ÔÓÚÿ¸öÕË»§£¬CREATE USER»áÔÚûÓÐȨÏÞµÄmysq ......
ÎÒʹÓõÄÊÇapserv°²×°°ü£¬°²×°Ê±ÓïÑÔÎÒÑ¡ÔñµÄÊÇgb2312£¬ºóÀ´ÔÚ½¨Á¢ÐµÄÊý¾Ý¿âʱ£¬‘ÕûÀí’Ñ¡ÔñµÄÊÇutf8£¬½ÓÏÂÀ´ÔÚ±íÖвÎÊýÀàÐÍ»ù±¾Ñ¡ÔñµÄ¶¼ÊÇutf8£¬½ÓÏÂÀ´ÎÒ¾ÍÖ±½Óµ÷ÓÃÀ²£¬¸Â¸Â£¬ÎÒдµÄÊÇÒ»¸ö¼òµ¥µÄÁôÑÔ±¾¡£×î¼òµ¥µÄ¶ÁÈ¡Êý¾Ý¿âдÈëÊý¾Ý¿âµÄ³ÌÐò£¬¸Â¸Â£¡Ææ¹ÖµÄÊÇÔÚÊý¾Ý¿âÀïÃæÖ±½Ó²Ù×÷ÖÐÎÄÏÔʾ¶¼ºÜÕý³£¡£¿ÉÊÇÒ»µ½Íø ......