Files
inquiry_robot/deploy/_remote_mysql_root_probe2.ps1
T

133 lines
5.1 KiB
PowerShell

# Probe MySQL root without Stop on Access Denied; find credential files.
$ErrorActionPreference = "Continue"
$iniPath = "C:\yutongda\tools\mysql-8.0.39-winx64\my.ini"
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
Write-Output "=== my.ini sections / password-ish keys (names only) ==="
Select-String -Path $iniPath -Pattern '^\s*\[|^\s*(password|user|port|datadir|basedir)\s*=' |
ForEach-Object {
$l = $_.Line
if ($l -match '(?i)password\s*=') {
$m = [regex]::Match($l, '(?i)password\s*=\s*(.*)$')
"password=<len=$($m.Groups[1].Value.Trim().Length)>"
} else { $l }
}
Write-Output "=== credential file names ==="
$paths = @(
"C:\yutongda\secure",
"C:\yutongda\config",
"C:\yutongda\ops",
"E:\wwwroot\ops",
"C:\yutongda\tools\mysql-8.0.39-winx64"
)
foreach ($p in $paths) {
if (Test-Path $p) {
Get-ChildItem $p -Recurse -File -ErrorAction SilentlyContinue |
Where-Object { $_.Name -match 'mysql|db|pass|secret|cred|root|admin' } |
Select-Object -First 40 |
ForEach-Object { $_.FullName }
}
}
Write-Output "=== try passwords from known secret files (no print) ==="
$secretFiles = @(
"C:\yutongda\secure\pgpass.txt",
"C:\yutongda\secure\redis-credentials.json",
"E:\wwwroot\ops\inquiry_robot_db_secrets.json",
"C:\yutongda\config\minio.env",
"C:\yutongda\config\minio-app.env"
)
# Also scan env files for MYSQL_ROOT or similar keys without printing values
$envCandidates = @()
foreach ($ef in @("C:\yutongda\.env","C:\yutongda\config\.env","E:\wwwroot\.env","C:\yutongda\secure\admin-secrets.env")) {
if (Test-Path $ef) {
Write-Output ("envfile=" + $ef)
Select-String -Path $ef -Pattern '^(MYSQL_|DB_|ROOT_|PG_|YTD_MYSQL)' |
ForEach-Object {
$k = ($_.Line -split '=',2)[0]
$v = if ($_.Line -match '=') { ($_.Line -split '=',2)[1] } else { "" }
Write-Output (" key=" + $k + " len=" + $v.Length)
if ($k -match 'PASSWORD|PASS|ROOT' -and $v.Length -gt 0) { $envCandidates += $v.Trim().Trim('"') }
}
}
}
# Collect candidate passwords from files that might store mysql root
$cands = New-Object System.Collections.Generic.List[string]
foreach ($f in $secretFiles) {
if (-not (Test-Path $f)) { continue }
Write-Output ("readfile=" + $f)
$raw = Get-Content $f -Raw -ErrorAction SilentlyContinue
if (-not $raw) { continue }
# JSON fields
if ($f -match '\.json$') {
try {
$j = $raw | ConvertFrom-Json
foreach ($prop in $j.PSObject.Properties) {
Write-Output (" jsonKey=" + $prop.Name + " type=" + $prop.Value.GetType().Name)
if ($prop.Name -match '(?i)pass|secret|pwd|root' -and ($prop.Value -is [string]) -and $prop.Value.Length -gt 0) {
$cands.Add([string]$prop.Value)
}
if ($prop.Value -is [psobject]) {
foreach ($p2 in $prop.Value.PSObject.Properties) {
Write-Output (" jsonKey=" + $prop.Name + "." + $p2.Name)
if ($p2.Name -match '(?i)pass|secret|pwd|root' -and ($p2.Value -is [string]) -and $p2.Value.Length -gt 0) {
$cands.Add([string]$p2.Value)
}
}
}
}
} catch {}
} else {
# KEY=VAL or bare password file
foreach ($line in ($raw -split "`r?`n")) {
if ($line -match '^\s*#' -or [string]::IsNullOrWhiteSpace($line)) { continue }
if ($line -match '^(?i)(MYSQL_ROOT_PASSWORD|MYSQL_PASSWORD|password|PASS)\s*=\s*(.+)$') {
$cands.Add($Matches[2].Trim().Trim('"'))
} elseif ($line -notmatch '=' -and $line.Trim().Length -ge 4 -and $line.Trim().Length -le 128) {
# bare password file like pgpass
$cands.Add($line.Trim())
}
}
}
}
foreach ($v in $envCandidates) { $cands.Add($v) }
# Common guesses last
foreach ($g in @("root","Root@123","Mysql@2026","MySQL@2026","mysql","Ytd@2026","YTD@2026","Postgres@2026","Admin@123","admin123","123456")) {
$cands.Add($g)
}
Write-Output ("candidates=" + $cands.Count)
$hit = $false
$seen = @{}
foreach ($p in $cands) {
if ([string]::IsNullOrWhiteSpace($p)) { continue }
if ($seen.ContainsKey($p)) { continue }
$seen[$p] = $true
$out = cmd /c "`"$mysql`" -uroot -p`"$p`" -e `"SELECT 'try_ok' AS r`" 2>&1"
$text = ($out | Out-String)
if ($text -match "try_ok") {
Write-Output ("HIT len=" + $p.Length)
$stash = "E:\wwwroot\ops\.mysql_root_stash.tmp"
Set-Content -Path $stash -Value $p -Encoding ascii -NoNewline
$hit = $true
break
}
}
if (-not $hit) { Write-Output "NO_HIT" }
Write-Output "=== PG inquiry_robot_runtime status ==="
$psql = "C:\yutongda\tools\pgsql\bin\psql.exe"
if (Test-Path $psql) {
$env:PGPASSWORD = (Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
& $psql -U postgres -h 127.0.0.1 -p 5432 -d postgres -tAc "SELECT datname FROM pg_database WHERE datname='inquiry_robot_runtime'" 2>&1
& $psql -U postgres -h 127.0.0.1 -p 5432 -d postgres -tAc "SELECT rolname FROM pg_roles WHERE rolname='inquiry_robot_runtime'" 2>&1
Remove-Item Env:PGPASSWORD -ErrorAction SilentlyContinue
}
Write-Output "=== .env host lines ==="
Select-String -Path "E:\wwwroot\.env" -Pattern '^(MYSQL_HOST|MYSQL_DB|MYSQL_USER|PG_HOST|PG_DATABASE|PG_USER)=' |
ForEach-Object { $_.Line }