98 lines
4.6 KiB
PowerShell
98 lines
4.6 KiB
PowerShell
# On 10.206.0.14: check if app roles can CREATE DATABASE / CREATEDB; try create if yes.
|
|
$ErrorActionPreference = "Continue"
|
|
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
|
|
$psql = "C:\yutongda\tools\pgsql\bin\psql.exe"
|
|
$dbCred = Get-Content "C:\yutongda\secure\application-database-credentials.json" -Raw | ConvertFrom-Json
|
|
$sec = Get-Content "E:\wwwroot\ops\inquiry_robot_db_secrets.json" -Raw | ConvertFrom-Json
|
|
$mh = [string]$dbCred.mysql_host
|
|
$ph = [string]$dbCred.postgres_host
|
|
|
|
Write-Output "=== PG: rolcreatedb / try create ==="
|
|
$env:PGPASSWORD = [string]$dbCred.postgres_password
|
|
$pgUser = [string]$dbCred.postgres_username
|
|
$pgDb = [string]$dbCred.postgres_database
|
|
& $psql -h $ph -p 5432 -U $pgUser -d $pgDb -tAc "SELECT rolname, rolsuper, rolcreatedb FROM pg_roles WHERE rolname=current_user;" 2>&1 | ForEach-Object { "$_" }
|
|
|
|
# Try create role+db (will fail without priv)
|
|
$pgPass = [string]$sec.pg_password
|
|
$pgNewUser = [string]$sec.pg_user
|
|
$createSql = @"
|
|
SELECT 1;
|
|
"@
|
|
# Check if we can create database
|
|
$try = & $psql -h $ph -p 5432 -U $pgUser -d $pgDb -v ON_ERROR_STOP=1 -c "CREATE DATABASE inquiry_robot_runtime_probe OWNER current_user;" 2>&1
|
|
$tryText = ($try | ForEach-Object {"$_"}) -join "`n"
|
|
if ($tryText -match "ERROR|FATAL|权限|permission|denied") {
|
|
Write-Output ("pg_create_db=" + (($tryText -split "`n" | Where-Object { $_ -match "ERROR|FATAL|denied|权限" } | Select-Object -First 1)))
|
|
} else {
|
|
Write-Output "pg_create_db=UNEXPECTED_OK"
|
|
& $psql -h $ph -p 5432 -U $pgUser -d $pgDb -c "DROP DATABASE inquiry_robot_runtime_probe;" 2>&1 | Out-Null
|
|
}
|
|
|
|
Write-Output "=== MySQL: privilege check ==="
|
|
$mu = [string]$dbCred.mysql_username
|
|
$mp = [string]$dbCred.mysql_password
|
|
& $mysql -h $mh -P 3306 -u $mu "-p$mp" --batch -e "SHOW GRANTS FOR CURRENT_USER(); SELECT COUNT(*) AS can_create FROM information_schema.user_privileges WHERE GRANTEE LIKE CONCAT(\"'\" , SUBSTRING_INDEX(CURRENT_USER(),'@',1) , \"%\") AND PRIVILEGE_TYPE='CREATE';" 2>&1 |
|
|
Where-Object { "$_" -notmatch "Warning" } | ForEach-Object { "$_" }
|
|
|
|
Write-Output "=== try root@dataHost with known password files (bool only) ==="
|
|
function Test-MysqlRoot([string]$pass) {
|
|
if ([string]::IsNullOrWhiteSpace($pass)) { return $false }
|
|
$out = & $mysql -h $mh -P 3306 -uroot "-p$pass" --connect-timeout=8 --batch -N -e "SELECT 1" 2>&1
|
|
$text = ($out | ForEach-Object {"$_"}) -join "`n"
|
|
if ($text -match "ERROR") { return $false }
|
|
$lines = $out | ForEach-Object {"$_".Trim()} | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
|
|
return ($lines -contains "1")
|
|
}
|
|
function Test-PgSuper([string]$user, [string]$pass) {
|
|
$env:PGPASSWORD = $pass
|
|
$out = & $psql -h $ph -p 5432 -U $user -d postgres -tAc "SELECT 1" 2>&1
|
|
return (($out | Out-String) -match "(?m)^\s*1\s*$")
|
|
}
|
|
|
|
$cands = New-Object System.Collections.Generic.List[object]
|
|
function Add-P([string]$src, [string]$pass) {
|
|
if ([string]::IsNullOrWhiteSpace($pass)) { return }
|
|
$cands.Add([pscustomobject]@{src=$src; pass=$pass; len=$pass.Length})
|
|
}
|
|
Add-P "app.mysql" ([string]$dbCred.mysql_password)
|
|
Add-P "app.pg" ([string]$dbCred.postgres_password)
|
|
Add-P "pgpass" ((Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim())
|
|
Add-P "sec.mysql" ([string]$sec.mysql_password)
|
|
Add-P "sec.pg" ([string]$sec.pg_password)
|
|
if (Test-Path "E:\wwwroot\ops\.mysql_root_stash.tmp") {
|
|
Add-P "stash" ((Get-Content "E:\wwwroot\ops\.mysql_root_stash.tmp" -Raw).Trim())
|
|
}
|
|
if (Test-Path "E:\wwwroot\ops\local_mysql_root_secret.json") {
|
|
Add-P "local_root_json" ([string](Get-Content "E:\wwwroot\ops\local_mysql_root_secret.json" -Raw | ConvertFrom-Json).root_password)
|
|
}
|
|
|
|
# Also scan prompt-like admin files on server if any
|
|
Get-ChildItem "E:\wwwroot\ops" -Filter "*secret*" -EA SilentlyContinue | ForEach-Object {
|
|
Write-Output ("ops_secret_file=" + $_.Name)
|
|
}
|
|
|
|
$mysqlHit = $false
|
|
$pgHit = $false
|
|
foreach ($c in $cands) {
|
|
if (-not $mysqlHit -and (Test-MysqlRoot $c.pass)) {
|
|
Write-Output ("MYSQL_ROOT_HIT src=" + $c.src + " len=" + $c.len)
|
|
Set-Content "E:\wwwroot\ops\.datahost_mysql_root.stash" -Value $c.pass -Encoding ascii -NoNewline
|
|
$mysqlHit = $true
|
|
}
|
|
if (-not $pgHit) {
|
|
foreach ($u in @("postgres","pgsql","admin","ytd_admin")) {
|
|
if (Test-PgSuper $u $c.pass) {
|
|
Write-Output ("PG_SUPER_HIT user=$u src=$($c.src) len=$($c.len)")
|
|
@{ user = $u; password = $c.pass } | ConvertTo-Json | Set-Content "E:\wwwroot\ops\.datahost_pg_super.stash.json" -Encoding UTF8
|
|
$pgHit = $true
|
|
break
|
|
}
|
|
}
|
|
}
|
|
}
|
|
if (-not $mysqlHit) { Write-Output "MYSQL_ROOT_NO_HIT" }
|
|
if (-not $pgHit) { Write-Output "PG_SUPER_NO_HIT" }
|
|
Remove-Item Env:PGPASSWORD -EA SilentlyContinue
|
|
Write-Output "DONE"
|