# Probe local MySQL root auth without printing secrets. $ErrorActionPreference = "Stop" $iniPath = "C:\yutongda\tools\mysql-8.0.39-winx64\my.ini" $mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe" Write-Output "=== my.ini password line shape ===" $ini = Get-Content $iniPath -Raw $hasPwdLine = [regex]::IsMatch($ini, "(?im)^\s*password\s*=") $m = [regex]::Match($ini, "(?im)^\s*password\s*=\s*(.*)$") $len = if ($m.Success) { $m.Groups[1].Value.Trim().Length } else { -1 } Write-Output ("hasPwdLine=" + $hasPwdLine + " valueLen=" + $len) Write-Output "=== try bare root (no -p) ===" & $mysql -uroot -e "SELECT 'bare_ok' AS r" 2>&1 | Select-Object -First 4 $candidates = @( "root", "Root@123", "Mysql@2026", "mysql", "admin", "Ytd@2026", "YTD@2026", "Postgres@2026", "Redis@2026" ) # Also try password from my.ini if present (do not print) if ($m.Success -and $len -gt 0) { $fromIni = $m.Groups[1].Value.Trim().Trim('"').Trim("'") $candidates = @($fromIni) + $candidates } Write-Output "=== try candidate passwords (only report hit) ===" $hit = $false foreach ($p in $candidates) { $out = & $mysql -uroot "-p$p" -e "SELECT 'try_ok' AS r" 2>&1 | Out-String if ($LASTEXITCODE -eq 0 -and $out -match "try_ok") { Write-Output ("HIT valueLen=" + $p.Length + " fromIni=" + ($p -eq ($candidates[0] -and $len -gt 0))) # stash for next script via protected file (ACL ytd_extdev only) $stash = "E:\wwwroot\ops\.mysql_root_stash.tmp" Set-Content -Path $stash -Value $p -Encoding ascii -NoNewline icacls $stash /inheritance:r | Out-Null icacls $stash /grant:r "${env:USERNAME}:(R)" | Out-Null $hit = $true break } } if (-not $hit) { Write-Output "NO_HIT" } Write-Output "=== look for other credential files ===" @( "C:\yutongda\secure\*", "C:\yutongda\config\*mysql*", "C:\yutongda\config\*db*", "E:\wwwroot\ops\*mysql*", "E:\wwwroot\ops\*secret*" ) | ForEach-Object { Get-ChildItem $_ -ErrorAction SilentlyContinue | ForEach-Object { Write-Output $_.FullName } }