133 lines
5.1 KiB
PowerShell
133 lines
5.1 KiB
PowerShell
# Probe MySQL root without Stop on Access Denied; find credential files.
|
|
$ErrorActionPreference = "Continue"
|
|
$iniPath = "C:\yutongda\tools\mysql-8.0.39-winx64\my.ini"
|
|
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
|
|
|
|
Write-Output "=== my.ini sections / password-ish keys (names only) ==="
|
|
Select-String -Path $iniPath -Pattern '^\s*\[|^\s*(password|user|port|datadir|basedir)\s*=' |
|
|
ForEach-Object {
|
|
$l = $_.Line
|
|
if ($l -match '(?i)password\s*=') {
|
|
$m = [regex]::Match($l, '(?i)password\s*=\s*(.*)$')
|
|
"password=<len=$($m.Groups[1].Value.Trim().Length)>"
|
|
} else { $l }
|
|
}
|
|
|
|
Write-Output "=== credential file names ==="
|
|
$paths = @(
|
|
"C:\yutongda\secure",
|
|
"C:\yutongda\config",
|
|
"C:\yutongda\ops",
|
|
"E:\wwwroot\ops",
|
|
"C:\yutongda\tools\mysql-8.0.39-winx64"
|
|
)
|
|
foreach ($p in $paths) {
|
|
if (Test-Path $p) {
|
|
Get-ChildItem $p -Recurse -File -ErrorAction SilentlyContinue |
|
|
Where-Object { $_.Name -match 'mysql|db|pass|secret|cred|root|admin' } |
|
|
Select-Object -First 40 |
|
|
ForEach-Object { $_.FullName }
|
|
}
|
|
}
|
|
|
|
Write-Output "=== try passwords from known secret files (no print) ==="
|
|
$secretFiles = @(
|
|
"C:\yutongda\secure\pgpass.txt",
|
|
"C:\yutongda\secure\redis-credentials.json",
|
|
"E:\wwwroot\ops\inquiry_robot_db_secrets.json",
|
|
"C:\yutongda\config\minio.env",
|
|
"C:\yutongda\config\minio-app.env"
|
|
)
|
|
# Also scan env files for MYSQL_ROOT or similar keys without printing values
|
|
$envCandidates = @()
|
|
foreach ($ef in @("C:\yutongda\.env","C:\yutongda\config\.env","E:\wwwroot\.env","C:\yutongda\secure\admin-secrets.env")) {
|
|
if (Test-Path $ef) {
|
|
Write-Output ("envfile=" + $ef)
|
|
Select-String -Path $ef -Pattern '^(MYSQL_|DB_|ROOT_|PG_|YTD_MYSQL)' |
|
|
ForEach-Object {
|
|
$k = ($_.Line -split '=',2)[0]
|
|
$v = if ($_.Line -match '=') { ($_.Line -split '=',2)[1] } else { "" }
|
|
Write-Output (" key=" + $k + " len=" + $v.Length)
|
|
if ($k -match 'PASSWORD|PASS|ROOT' -and $v.Length -gt 0) { $envCandidates += $v.Trim().Trim('"') }
|
|
}
|
|
}
|
|
}
|
|
|
|
# Collect candidate passwords from files that might store mysql root
|
|
$cands = New-Object System.Collections.Generic.List[string]
|
|
foreach ($f in $secretFiles) {
|
|
if (-not (Test-Path $f)) { continue }
|
|
Write-Output ("readfile=" + $f)
|
|
$raw = Get-Content $f -Raw -ErrorAction SilentlyContinue
|
|
if (-not $raw) { continue }
|
|
# JSON fields
|
|
if ($f -match '\.json$') {
|
|
try {
|
|
$j = $raw | ConvertFrom-Json
|
|
foreach ($prop in $j.PSObject.Properties) {
|
|
Write-Output (" jsonKey=" + $prop.Name + " type=" + $prop.Value.GetType().Name)
|
|
if ($prop.Name -match '(?i)pass|secret|pwd|root' -and ($prop.Value -is [string]) -and $prop.Value.Length -gt 0) {
|
|
$cands.Add([string]$prop.Value)
|
|
}
|
|
if ($prop.Value -is [psobject]) {
|
|
foreach ($p2 in $prop.Value.PSObject.Properties) {
|
|
Write-Output (" jsonKey=" + $prop.Name + "." + $p2.Name)
|
|
if ($p2.Name -match '(?i)pass|secret|pwd|root' -and ($p2.Value -is [string]) -and $p2.Value.Length -gt 0) {
|
|
$cands.Add([string]$p2.Value)
|
|
}
|
|
}
|
|
}
|
|
}
|
|
} catch {}
|
|
} else {
|
|
# KEY=VAL or bare password file
|
|
foreach ($line in ($raw -split "`r?`n")) {
|
|
if ($line -match '^\s*#' -or [string]::IsNullOrWhiteSpace($line)) { continue }
|
|
if ($line -match '^(?i)(MYSQL_ROOT_PASSWORD|MYSQL_PASSWORD|password|PASS)\s*=\s*(.+)$') {
|
|
$cands.Add($Matches[2].Trim().Trim('"'))
|
|
} elseif ($line -notmatch '=' -and $line.Trim().Length -ge 4 -and $line.Trim().Length -le 128) {
|
|
# bare password file like pgpass
|
|
$cands.Add($line.Trim())
|
|
}
|
|
}
|
|
}
|
|
}
|
|
foreach ($v in $envCandidates) { $cands.Add($v) }
|
|
|
|
# Common guesses last
|
|
foreach ($g in @("root","Root@123","Mysql@2026","MySQL@2026","mysql","Ytd@2026","YTD@2026","Postgres@2026","Admin@123","admin123","123456")) {
|
|
$cands.Add($g)
|
|
}
|
|
|
|
Write-Output ("candidates=" + $cands.Count)
|
|
$hit = $false
|
|
$seen = @{}
|
|
foreach ($p in $cands) {
|
|
if ([string]::IsNullOrWhiteSpace($p)) { continue }
|
|
if ($seen.ContainsKey($p)) { continue }
|
|
$seen[$p] = $true
|
|
$out = cmd /c "`"$mysql`" -uroot -p`"$p`" -e `"SELECT 'try_ok' AS r`" 2>&1"
|
|
$text = ($out | Out-String)
|
|
if ($text -match "try_ok") {
|
|
Write-Output ("HIT len=" + $p.Length)
|
|
$stash = "E:\wwwroot\ops\.mysql_root_stash.tmp"
|
|
Set-Content -Path $stash -Value $p -Encoding ascii -NoNewline
|
|
$hit = $true
|
|
break
|
|
}
|
|
}
|
|
if (-not $hit) { Write-Output "NO_HIT" }
|
|
|
|
Write-Output "=== PG inquiry_robot_runtime status ==="
|
|
$psql = "C:\yutongda\tools\pgsql\bin\psql.exe"
|
|
if (Test-Path $psql) {
|
|
$env:PGPASSWORD = (Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
|
|
& $psql -U postgres -h 127.0.0.1 -p 5432 -d postgres -tAc "SELECT datname FROM pg_database WHERE datname='inquiry_robot_runtime'" 2>&1
|
|
& $psql -U postgres -h 127.0.0.1 -p 5432 -d postgres -tAc "SELECT rolname FROM pg_roles WHERE rolname='inquiry_robot_runtime'" 2>&1
|
|
Remove-Item Env:PGPASSWORD -ErrorAction SilentlyContinue
|
|
}
|
|
|
|
Write-Output "=== .env host lines ==="
|
|
Select-String -Path "E:\wwwroot\.env" -Pattern '^(MYSQL_HOST|MYSQL_DB|MYSQL_USER|PG_HOST|PG_DATABASE|PG_USER)=' |
|
|
ForEach-Object { $_.Line }
|