Files
inquiry_robot/deploy/_remote_mysql_yml_creds.ps1
T

92 lines
4.6 KiB
PowerShell

# Read prod yml mysql username near jdbc url (password length only); try that against local.
$ErrorActionPreference = "Continue"
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
$candidates = @(
"C:\yutongda\config\application-prod.yml",
"C:\yutongda\jeecg-boot\jeecg-module-system\jeecg-system-start\src\main\resources\application-prod.yml"
)
# Find actual running jar's external config
Write-Output "=== locate live spring config ==="
Get-ChildItem "C:\yutongda" -Recurse -Include "application-prod.yml","application-prod.yaml","application.yml" -EA SilentlyContinue -Depth 5 |
Where-Object { $_.FullName -match 'config|resources|wwwroot|yutongda\\config' -or $_.DirectoryName -match 'config$' } |
Select-Object -First 20 FullName, Length, LastWriteTime |
ForEach-Object { "$($_.LastWriteTime) $($_.Length) $($_.FullName)" }
Write-Output "=== extract datasource user/url from likely live files ==="
$files = @()
$files += Get-ChildItem "C:\yutongda\config" -Filter "*.yml" -EA SilentlyContinue
$files += Get-ChildItem "C:\yutongda\config" -Filter "*.yaml" -EA SilentlyContinue
$files += Get-ChildItem "C:\yutongda\config" -Filter "*.properties" -EA SilentlyContinue
$files += Get-ChildItem "E:\wwwroot" -Recurse -Include "application*.yml","application*.yaml" -EA SilentlyContinue -Depth 4
foreach ($f in $files) {
if (-not $f) { continue }
$hits = Select-String -Path $f.FullName -Pattern "jdbc:mysql|username:|password:|url:" -EA SilentlyContinue |
Select-Object -First 20
if (-not $hits) { continue }
Write-Output ("FILE=" + $f.FullName)
foreach ($h in $hits) {
$line = $h.Line.Trim()
if ($line -match '(?i)password') {
$m = [regex]::Match($line, '(?i)password:\s*(.+)$')
$len = if ($m.Success) { $m.Groups[1].Value.Trim().Trim('"').Length } else { -1 }
Write-Output (" L$($h.LineNumber) password: <len=$len>")
} else {
Write-Output (" L$($h.LineNumber) " + $line.Substring(0, [Math]::Min(180, $line.Length)))
}
}
}
# Try username/password pairs from application-database-credentials AND from any yml we can parse without printing
Write-Output "=== try credential pairs on 127.0.0.1 ==="
function Test-Login([string]$user, [string]$pass) {
if ([string]::IsNullOrWhiteSpace($user) -or [string]::IsNullOrWhiteSpace($pass)) { return $false }
$out = & $mysql -h127.0.0.1 -P3306 "-u$user" "-p$pass" --connect-timeout=5 --batch -N -e "SELECT 1" 2>&1
$text = ($out | ForEach-Object {"$_"}) -join "`n"
if ($text -match "ERROR\s+\d+") { return $false }
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
return ($lines -contains "1")
}
$dbCred = Get-Content "C:\yutongda\secure\application-database-credentials.json" -Raw | ConvertFrom-Json
$pairs = @()
$pairs += @{ u = [string]$dbCred.mysql_username; p = [string]$dbCred.mysql_password; src = "secure.json" }
# Parse yml-ish username/password contiguous blocks from C:\yutongda\config
Get-ChildItem "C:\yutongda\config" -Include *.yml,*.yaml,*.properties -Recurse -EA SilentlyContinue | ForEach-Object {
$lines = Get-Content $_.FullName
for ($i = 0; $i -lt $lines.Count; $i++) {
if ($lines[$i] -match 'jdbc:mysql://(127\.0\.0\.1|localhost)') {
$user = $null; $pass = $null
for ($j = [Math]::Max(0,$i-5); $j -le [Math]::Min($lines.Count-1, $i+8); $j++) {
if ($lines[$j] -match '^\s*username:\s*(\S+)\s*$') { $user = $Matches[1].Trim('"') }
if ($lines[$j] -match '^\s*password:\s*(.+)\s*$') { $pass = $Matches[1].Trim().Trim('"') }
if ($lines[$j] -match '^\s*username=(.+)$') { $user = $Matches[1].Trim() }
if ($lines[$j] -match '^\s*password=(.+)$') { $pass = $Matches[1].Trim() }
}
if ($user -and $pass) {
$pairs += @{ u = $user; p = $pass; src = $_.Name }
}
}
}
}
Write-Output ("pairs=" + $pairs.Count)
foreach ($pair in $pairs) {
$ok = Test-Login $pair.u $pair.p
Write-Output ("ok=$ok user=$($pair.u) src=$($pair.src) passLen=$($pair.p.Length)")
if ($ok) {
$g = & $mysql -h127.0.0.1 -P3306 "-u$($pair.u)" "-p$($pair.p)" --batch -e "SHOW GRANTS FOR CURRENT_USER(); SELECT SCHEMA_NAME FROM information_schema.SCHEMATA;" 2>&1 | Out-String
($g -split "`r?`n" | Where-Object { $_ -match "GRANT|SCHEMA|jeecg|inquiry|Database" } | Select-Object -First 40) | ForEach-Object { " $_" }
if ($g -match "CREATE|ALL PRIVILEGES ON \*\.\*|WITH GRANT OPTION" -or $pair.u -eq "root") {
Set-Content "E:\wwwroot\ops\.mysql_root_stash.tmp" -Value $pair.p -Encoding ascii -NoNewline
Set-Content "E:\wwwroot\ops\.mysql_admin_user.txt" -Value $pair.u -Encoding ascii
Write-Output "ADMIN_CANDIDATE_STASHED"
}
}
}
Write-Output "DONE2"