浣跨敤MySQL錛屽畨鍏ㄩ棶棰樹笉鑳戒笉娉ㄦ剰銆備互涓嬫槸MySQL鎻愮ず鐨?span lang="EN-US">23涓敞鎰忎簨欏?span lang="EN-US">:
銆銆浣跨敤MySQL錛屽畨鍏ㄩ棶棰樹笉鑳戒笉娉ㄦ剰銆備互涓嬫槸MySQL鎻愮ず鐨?span lang="EN-US">23涓敞鎰忎簨欏?span lang="EN-US">:
銆銆1.濡傛灉瀹㈡埛绔拰鏈嶅姟鍣ㄧ鐨勮繛鎺ラ渶瑕佽法瓚婂茍閫氳繃涓嶅彲淇′換鐨勭綉緇滐紝閭d箞灝遍渶瑕佷嬌鐢?span lang="EN-US">SSH闅ч亾鏉ュ姞瀵嗚榪炴帴鐨勯氫俊銆?/p>
銆銆2.鐢?span lang="EN-US">set password璇彞鏉ヤ慨鏀圭敤鎴風殑瀵嗙爜錛屼笁涓楠わ紝鍏?span lang="EN-US">“mysql -u root”鐧婚檰鏁版嵁搴撶郴緇燂紝鐒跺悗“mysql> update
mysql.user set password=password('newpwd')”錛屾渶鍚庢墽琛?span lang="EN-US">“flush
privileges”灝卞彲浠ヤ簡銆?/p>
銆銆3.闇瑕佹彁闃茬殑鏀誨嚮鏈夛紝闃插伔鍚佺鏀廣佸洖鏀俱佹嫆緇濇湇鍔$瓑錛屼笉娑夊強鍙敤鎬у拰瀹歸敊鏂歸潰銆傚鎵鏈夌殑榪炴帴銆佹煡璇€佸叾浠栨搷浣滀嬌鐢ㄥ熀浜?span lang="EN-US">ACL鍗寵闂帶鍒跺垪琛ㄧ殑瀹夊叏鎺柦鏉ュ畬鎴愩備篃鏈変竴浜涘SSL榪炴帴鐨勬敮鎸併?/p>
銆銆4.闄や簡root鐢ㄦ埛澶栫殑鍏朵粬浠諱綍鐢ㄦ埛涓嶅厑璁歌闂?span lang="EN-US">mysql涓繪暟鎹簱涓殑user琛?span lang="EN-US">;
銆銆鍔犲瘑鍚庡瓨鏀懼湪user琛ㄤ腑鐨勫姞瀵嗗悗鐨勭敤鎴峰瘑鐮佷竴鏃︽硠闇詫紝鍏朵粬浜哄彲浠ラ殢鎰忕敤璇ョ敤鎴峰悕/瀵嗙爜鐩稿簲鐨勬暟鎹簱;
銆銆5.鐢?span lang="EN-US">grant鍜?span lang="EN-US">revoke璇彞鏉ヨ繘琛岀敤鎴瘋闂帶鍒剁殑宸ヤ綔;
銆銆6.涓嶄嬌鐢ㄦ槑鏂囧瘑鐮侊紝鑰屾槸浣跨敤md5()鍜?span lang="EN-US">sha1()絳夊崟鍚戠殑鍝堢郴鍑芥暟鏉ヨ緗瘑鐮?span lang="EN-US">;
銆銆7.涓嶉夌敤瀛楀吀涓殑瀛楁潵鍋氬瘑鐮?span lang="EN-US">;
銆銆8.閲囩敤闃茬伀澧欐潵鍘繪帀50%鐨勫閮ㄥ嵄闄╋紝璁╂暟鎹簱緋葷粺韜插湪闃茬伀澧欏悗闈㈠伐浣滐紝鎴栨斁緗湪DMZ鍖哄煙涓?span lang="EN-US">;
銆銆9.浠庡洜鐗圭綉涓婄敤nmap鏉ユ壂鎻?span lang="EN-US">3306绔彛錛屼篃鍙敤telnet server_host 3306鐨勬柟娉曟祴璇曪紝涓嶈兘鍏佽浠庨潪淇′換緗戠粶涓闂暟鎹簱鏈嶅姟鍣ㄧ殑3306鍙?span lang="EN-US">TCP绔彛錛屽洜姝ら渶瑕佸湪闃茬伀澧欐垨璺敱鍣ㄤ笂鍋氳瀹?span lang="EN-US">;
銆銆10.涓轟簡闃叉琚伓鎰忎紶鍏ラ潪娉曞弬鏁幫紝渚嬪where ID=234錛屽埆浜哄嵈杈撳叆where ID=234 OR 1=1瀵艱嚧鍏ㄩ儴鏄劇ず錛屾墍浠ュ湪web鐨勮〃鍗曚腑浣跨敤''鎴?span lang="EN-US">""鏉ョ敤瀛楃涓詫紝鍦ㄥ姩鎬?span lang="EN-US">URL涓姞鍏?span lang="EN-US">%22浠h〃鍙屽紩鍙楓?span lang="EN-US">%23浠h〃浜曞彿銆?span lang="EN-US">%27浠h〃鍗曞紩鍙?span lang="EN-US">;浼犻掓湭媯 鏌ヨ繃鐨勫肩粰mysql鏁版嵁搴撴槸闈炲父鍗遍櫓鐨?span lang="EN-US">;
銆銆11.鍦ㄤ紶閫掓暟鎹粰mysql鏃舵鏌ヤ竴涓嬪ぇ灝?span lang="EN-US">;
銆銆12.搴旂敤紼嬪簭闇瑕佽繛鎺ュ埌鏁版嵁搴撳簲璇ヤ嬌鐢ㄤ竴鑸殑鐢ㄦ埛甯愬彿錛屽彧寮鏀懼皯鏁板繀瑕佺殑鏉冮檺緇欒鐢ㄦ埛;
銆銆13.鍦ㄥ悇緙栫▼鎺ュ彛(C C++ PHP Perl Java
JDBC絳?span lang="EN-US">)涓嬌鐢ㄧ壒瀹?span lang="EN-US">‘閫冭劚瀛楃’鍑芥暟;
銆銆鍦ㄥ洜鐗圭綉涓婁嬌鐢?span lang="EN-US">mysql鏁版嵁搴撴椂涓瀹氬皯鐢ㄤ紶杈撴槑鏂囩殑鏁版嵁錛岃岀敤SSL鍜?span lang="EN-US">SSH鐨勫姞瀵嗘柟寮忔暟鎹潵浼犺緭;
銆銆14.瀛︿細浣跨敤tcpdump鍜?span lang="EN-US">strings宸ュ叿鏉ユ煡鐪嬩紶杈撴暟鎹殑瀹夊叏鎬э紝渚嬪tcpdump -l -i eth0 -w
-src or dst port 3306 | strings銆備互鏅氱敤鎴鋒潵鍚姩mysql鏁版嵁搴撴湇鍔?span lang="EN-US">;
銆銆15.涓嶄嬌鐢ㄥ埌琛ㄧ殑鑱旂粨絎﹀彿錛岄夌敤鐨勫弬鏁?span lang="EN-US">
--skip-symbolic-links;
銆銆16.紜俊鍦?span lang="EN-US">mysql鐩綍涓彧鏈夊惎鍔ㄦ暟鎹簱鏈嶅姟鐨勭敤鎴鋒墠鍙互瀵規(guī)枃浠舵湁璇誨拰鍐欑殑鏉冮檺;
銆銆17.涓嶈灝?span lang="EN-US">process鎴?span lang="EN-US">super鏉冮檺浠樼粰闈炵鐞嗙敤鎴鳳紝璇?span lang="EN-US">mysqladmin processlist鍙互鍒椾婦鍑哄綋鍓嶆墽琛岀殑鏌ヨ鏂囨湰;super鏉冮檺鍙敤浜庡垏鏂鎴風榪炴帴銆佹敼鍙樻湇鍔″櫒榪愯鍙傛暟鐘舵併佹帶鍒舵嫹璐濆鍒舵暟鎹簱鐨勬湇鍔″櫒;
銆銆18.file鏉冮檺涓嶄粯緇欑鐞嗗憳浠ュ鐨勭敤鎴鳳紝闃叉鍑虹幇load
data '/etc/passwd'鍒拌〃涓啀鐢?span lang="EN-US">select 鏄劇ず鍑烘潵鐨勯棶棰?span lang="EN-US">;
銆銆19.濡傛灉涓嶇浉淇?span lang="EN-US">DNS鏈嶅姟鍏徃鐨勬湇鍔★紝鍙互鍦ㄤ富鏈哄悕縐板厑璁歌〃涓彧璁劇疆IP鏁板瓧鍦板潃;
銆銆20.浣跨敤max_user_connections鍙橀噺鏉ヤ嬌mysqld鏈嶅姟榪涚▼錛屽涓涓寚瀹氬笎鎴烽檺瀹氳繛鎺ユ暟;
銆銆21.grant璇彞涔熸敮鎸佽祫婧愭帶鍒墮夐」;
銆銆22.鍚姩mysqld鏈嶅姟榪涚▼鐨勫畨鍏ㄩ夐」寮鍏籌紝--local-infile=0鎴?span lang="EN-US">1 鑻ユ槸0鍒欏鎴風紼嬪簭灝辨棤娉曚嬌鐢?span lang="EN-US">local load data浜嗭紝璧嬫潈鐨勪竴涓緥瀛?span lang="EN-US">grant insert(user) on mysql.user to 'user_name'@'host_name';鑻ヤ嬌鐢?span lang="EN-US">--skip-grant-tables緋葷粺灝嗗浠諱綍鐢ㄦ埛鐨勮闂笉鍋氫換浣曡闂帶鍒訛紝浣嗗彲浠ョ敤
mysqladmin flush-privileges鎴?span lang="EN-US">mysqladmin reload鏉ュ紑鍚闂帶鍒?span lang="EN-US">;榛樿鎯呭喌鏄?span lang="EN-US">show databases璇彞瀵規(guī)墍鏈夌敤鎴峰紑鏀撅紝鍙互鐢?span lang="EN-US">--skip-show-databases鏉ュ叧闂帀銆?/p>
銆銆23.紕板埌Error 1045(28000) Access
Denied for user 'root'@'localhost' (Using password:NO)閿欒鏃訛紝浣犻渶瑕侀噸鏂拌緗瘑鐮侊紝鍏蜂綋鏂規(guī)硶鏄?span lang="EN-US">:鍏堢敤--skip-grant-tables鍙傛暟鍚姩mysqld錛岀劧鍚庢墽琛?span lang="EN-US"> mysql -u root
mysql,mysql>update user set password=password('newpassword') where
user='root';mysql>Flush privileges;錛屾渶鍚庨噸鏂板惎鍔?span lang="EN-US">mysql灝卞彲浠ヤ簡

]]>