When using MySQL, security issues cannot be ignored. The following are 23 notes from MySQL:
1. If the connection between the client and the server needs to span and pass through an untrusted network, then you need to use an SSH tunnel to encrypt the communication of the connection.
2. Use the set passWord statement to change the user's password. Three steps. First log in to the database system with "mysql -u root", then "mysql> update mysql.user set password=password('newpwd')", and finally execute Just “flush PRivileges”.
3. Attacks that need to be guarded against include anti-eavesdropping, tampering, replay, denial of service, etc., which do not involve availability and fault tolerance. All connections, queries, and other operations are completed using security measures based on ACL (access control list). There is also some support for SSL connections.
4. Any other user except the root user is not allowed to access the user table in the mysql main database;
Once the encrypted user password stored in the user table is leaked, others can use the user name at will/ Database corresponding to the password; 5. Use grant and revoke statements to perform user access control work; 6. Do not use plain text passwords, but use one-way hash functions such as md5() and sha1() to set them Password;
7. Do not use words in the dictionary as passwords;
8. Use firewalls to remove 50% of external risks, and let the database system work behind the firewall, or place it in the DMZ zone;
9. Use nmap to scan port 3306 from the Internet, or use telnet server_host 3306 to test. Access to TCP port 3306 of the database server from an untrusted network is not allowed, so settings need to be made on the firewall or router;
10. In order to prevent illegal parameters from being maliciously passed in, such as where ID=234, but others enter where ID=234 OR 1=1, causing all to be displayed, so use '' or "" to use strings in the web form, and use strings in the dynamic URL Adding %22 represents double quotes, %23 represents pound sign, and %27 represents single quotes; it is very dangerous to pass unchecked values to the mysql database;
11. Check the size when passing data to mysql;
12. Applications that need to connect to the database should use a general user account, and only open a few necessary permissions to the user; 13. Use specific 'escape character' functions in various programming interfaces (C C++ php Perl java JDBC, etc.) ;
When using mysql database on the Internet, be sure not to transmit plain text data, and use SSL and SSH encryption to transmit data;
14. Learn to use tcpdump and strings tools to check the security of transmitted data, such as tcpdump -l -i eth0 -w -src or dst port 3306 strings. Start the mysql database service as an ordinary user;
15. Do not use the link symbol of the table, select the parameter --skip-symbolic-links; 16. Make sure that only the user who starts the database service in the mysql directory can access the database service. The file has read and write permissions;
17. Process or super permissions are not allowed to be given to non-administrative users. The mysqladmin processlist can list the currently executed query text; super permissions can be used to cut off client connections and change the status of server operating parameters. , control the server that copies and replicates the database;
18. File permissions are not given to users other than administrators to prevent the problem of loading data '/etc/passwd' into the table and then using select to display it;
19. If not If you believe in the service of the DNS service company, you can only set the IP numeric address in the host name permission table;
20. Use the max_user_connections variable to make the mysqld service process limit the number of connections for a specified account;
21. The grant statement also supports resources Control options;
22. Start the security option switch of the mysqld service process, --local-infile=0 or 1. If it is 0, the client program cannot use local load data. An example of grant grant insert(user) on mysql.user to 'user_name'@'host_name'; If you use --skip-grant-tables, the system will not perform any access control on any user's access, but you can use mysqladmin flush-privileges or mysqladmin reload to enable access control; default The situation is that the show databases statement is open to all users and can be turned off with --skip-show-databases.
23. When encountering Error 1045 (28000) access Denied for user 'root'@'localhost' (Using password:NO), you need to reset the password. The specific method is: first use --skip-grant-tables Start mysqld with the parameters, then execute mysql -u root mysql,mysql>update user set password=password('newpassword') where user='root';mysql>Flush privileges;, and finally restart mysql.
The above is the content of Mysql security precautions. For more related articles, please pay attention to the PHP Chinese website (www.php.cn)!

本篇文章给大家带来了关于mysql的相关知识,其中主要介绍了关于架构原理的相关内容,MySQL Server架构自顶向下大致可以分网络连接层、服务层、存储引擎层和系统文件层,下面一起来看一下,希望对大家有帮助。

方法:1、利用right函数,语法为“update 表名 set 指定字段 = right(指定字段, length(指定字段)-1)...”;2、利用substring函数,语法为“select substring(指定字段,2)..”。

mysql的msi与zip版本的区别:1、zip包含的安装程序是一种主动安装,而msi包含的是被installer所用的安装文件以提交请求的方式安装;2、zip是一种数据压缩和文档存储的文件格式,msi是微软格式的安装包。

在mysql中,可以利用char()和REPLACE()函数来替换换行符;REPLACE()函数可以用新字符串替换列中的换行符,而换行符可使用“char(13)”来表示,语法为“replace(字段名,char(13),'新字符串') ”。

转换方法:1、利用cast函数,语法“select * from 表名 order by cast(字段名 as SIGNED)”;2、利用“select * from 表名 order by CONVERT(字段名,SIGNED)”语句。

本篇文章给大家带来了关于mysql的相关知识,其中主要介绍了关于MySQL复制技术的相关问题,包括了异步复制、半同步复制等等内容,下面一起来看一下,希望对大家有帮助。

本篇文章给大家带来了关于mysql的相关知识,其中主要介绍了mysql高级篇的一些问题,包括了索引是什么、索引底层实现等等问题,下面一起来看一下,希望对大家有帮助。

在mysql中,可以利用REGEXP运算符判断数据是否是数字类型,语法为“String REGEXP '[^0-9.]'”;该运算符是正则表达式的缩写,若数据字符中含有数字时,返回的结果是true,反之返回的结果是false。


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Dreamweaver CS6
Visual web development tools

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

WebStorm Mac version
Useful JavaScript development tools

Atom editor mac version download
The most popular open source editor

MinGW - Minimalist GNU for Windows
This project is in the process of being migrated to osdn.net/projects/mingw, you can continue to follow us there. MinGW: A native Windows port of the GNU Compiler Collection (GCC), freely distributable import libraries and header files for building native Windows applications; includes extensions to the MSVC runtime to support C99 functionality. All MinGW software can run on 64-bit Windows platforms.
