75 lines
3.4 KiB
PowerShell
75 lines
3.4 KiB
PowerShell
# Find who uses local MySQL 127.0.0.1 / localhost and any root/admin passwords (keys only + try).
|
|
$ErrorActionPreference = "Continue"
|
|
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
|
|
|
|
Write-Output "=== config refs to local mysql ==="
|
|
Get-ChildItem "C:\yutongda" -Recurse -Include *.yml,*.yaml,*.env,*.properties,*.json,*.xml,*.conf -EA SilentlyContinue -Depth 6 |
|
|
Select-String -Pattern "127\.0\.0\.1:3306|localhost:3306|jdbc:mysql://127|jdbc:mysql://localhost" -EA SilentlyContinue |
|
|
Select-Object -First 40 |
|
|
ForEach-Object {
|
|
$t = $_.Line.Trim()
|
|
if ($t -match 'password|passwd') { "F=$($_.Filename):$($_.LineNumber) REDACTED" }
|
|
else { "F=$($_.Filename):$($_.LineNumber) $($t.Substring(0,[Math]::Min(160,$t.Length)))" }
|
|
}
|
|
|
|
Write-Output "=== err log head (init / password lines redacted) ==="
|
|
$errFile = "C:\yutongda\data\mysql\10_206_0_15.err"
|
|
Get-Content $errFile -TotalCount 50 | ForEach-Object {
|
|
$_ -replace '(?i)(password[^\r\n]*?:\s*)\S+','$1***' `
|
|
-replace '(?i)([Pp]assword\s*=\s*)\S+','$1***'
|
|
}
|
|
|
|
Write-Output "=== netstat who connects to 3306 ==="
|
|
Get-NetTCPConnection -LocalPort 3306 -EA SilentlyContinue |
|
|
Group-Object State | ForEach-Object { "$($_.Name)=$($_.Count)" }
|
|
Get-NetTCPConnection -LocalPort 3306 -State Established -EA SilentlyContinue |
|
|
Select-Object -First 15 RemoteAddress,RemotePort,OwningProcess |
|
|
ForEach-Object {
|
|
$p = Get-Process -Id $_.OwningProcess -EA SilentlyContinue
|
|
"remote=$($_.RemoteAddress):$($_.RemotePort) pid=$($_.OwningProcess) name=$($p.ProcessName)"
|
|
}
|
|
|
|
Write-Output "=== try passwords from prompt-like hex in secure json against local with OTHER usernames ==="
|
|
# Common local admin names
|
|
$dbCred = Get-Content "C:\yutongda\secure\application-database-credentials.json" -Raw | ConvertFrom-Json
|
|
$passes = @(
|
|
[string]$dbCred.mysql_password,
|
|
[string]$dbCred.postgres_password,
|
|
(Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
|
|
)
|
|
# From e2e
|
|
$e2e = Get-Content "C:\yutongda\secure\e2e-business-20260826-205407.env" -EA SilentlyContinue
|
|
foreach ($line in $e2e) {
|
|
if ($line -match 'PASSWORD=(.+)$') { $passes += $Matches[1].Trim() }
|
|
}
|
|
|
|
$users = @("root","mysql","admin","ytd","ytd_admin","ytd_root","ytd_jeecg","jeecg","replicator")
|
|
function Test-Login([string]$user, [string]$pass) {
|
|
$out = & $mysql -h127.0.0.1 -P3306 "-u$user" "-p$pass" --connect-timeout=5 --batch -N -e "SELECT 1" 2>&1
|
|
$text = ($out | ForEach-Object {"$_"}) -join "`n"
|
|
if ($text -match "ERROR\s+\d+") { return $false }
|
|
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
|
|
return ($lines -contains "1")
|
|
}
|
|
|
|
$hit = $false
|
|
foreach ($u in $users) {
|
|
foreach ($p in $passes) {
|
|
if ([string]::IsNullOrWhiteSpace($p)) { continue }
|
|
if (Test-Login $u $p) {
|
|
Write-Output ("LOCAL_HIT user=$u passLen=$($p.Length)")
|
|
# check grants
|
|
$g = & $mysql -h127.0.0.1 -P3306 "-u$u" "-p$p" --batch -e "SHOW GRANTS FOR CURRENT_USER(); SHOW DATABASES;" 2>&1 | Out-String
|
|
($g -split "`r?`n" | Where-Object { $_ -match "GRANT|Database|^[a-z0-9_-]+$" } | Select-Object -First 30) | ForEach-Object { " $_" }
|
|
if ($u -eq "root" -or $g -match "ALL PRIVILEGES ON \*\.\*") {
|
|
Set-Content "E:\wwwroot\ops\.mysql_root_stash.tmp" -Value $p -Encoding ascii -NoNewline
|
|
Set-Content "E:\wwwroot\ops\.mysql_admin_user.txt" -Value $u -Encoding ascii
|
|
}
|
|
$hit = $true
|
|
}
|
|
}
|
|
}
|
|
if (-not $hit) { Write-Output "NO_LOCAL_USER_HIT" }
|
|
|
|
Write-Output "DONE"
|