簡體   English   中英

如何檢查通過php是否可訪問的mysql表

[英]How to check a mysql table accessible or not via php

我有一個自托管的Web應用程序,我試圖訪問information_schema表,以了解如何在某些服務器中將其禁用。 如何檢查它是否可訪問?

示例解決方案若要解決此問題:

  <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
        "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
    <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
    <head>
    <title>MySQL Connection Test</title>
    <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
    <style type="text/css">
    #wrapper {
        width: 600px;
        margin: 20px auto 0;
        font: 1.2em Verdana, Arial, sans-serif;
    }
    input {
        font-size: 1em;
    }
    #submit {
        padding: 4px 8px;
    }
    </style>
    </head>

    <body>

    <div id="wrapper">

    <?php
        $action = htmlspecialchars($_GET['action'], ENT_QUOTES);
    ?>

    <?php if (!$action) { ?>

        <h1>MySQL connection test</h1>

    <form action="<?php echo $_SERVER['PHP_SELF']; ?>?action=test" id="mail" method="post">

        <table cellpadding="2">
            <tr>
                <td>Hostname</td>
                <td><input type="text" name="hostname" id="hostname" value="" size="30" tabindex="1" /></td>
                <td>(usually "localhost")</td>
            </tr>
            <tr>
                <td>Username</td>
                <td><input type="text" name="username" id="username" value="" size="30" tabindex="2" /></td>
                <td></td>
            </tr>
            <tr>
                <td>Password</td>
                <td><input type="text" name="password" id="password" value="" size="30" tabindex="3" /></td>
                <td></td>
            </tr>
            <tr>
                <td>Database</td>
                <td><input type="text" name="database" id="database" value="" size="30" tabindex="4" /></td>
                <td>(optional)</td>
            </tr>
            <tr>
                <td></td>
                <td><input type="submit" id="submit" value="Test Connection" tabindex="5" /></td>
                <td></td>
            </tr>
        </table>

    </form>

    <?php } ?>

    <?php if ($action == "test") {

    // The variables have not been adequately sanitized to protect against SQL Injection attacks: http://us3.php.net/mysql_real_escape_string

        $hostname = trim($_POST['hostname']);
        $username = trim($_POST['username']);
        $password = trim($_POST['password']);
        $database = trim($_POST['database']);

        $link = mysql_connect("$hostname", "$username", "$password");
            if (!$link) {
                echo "<p>Could not connect to the server '" . $hostname . "'</p>\n";
                echo mysql_error();
            }else{
                echo "<p>Successfully connected to the server '" . $hostname . "'</p>\n";
    //          printf("MySQL client info: %s\n", mysql_get_client_info());
    //          printf("MySQL host info: %s\n", mysql_get_host_info());
    //          printf("MySQL server version: %s\n", mysql_get_server_info());
    //          printf("MySQL protocol version: %s\n", mysql_get_proto_info());
            }
        if ($link && !$database) {
            echo "<p>No database name was given. Available databases:</p>\n";
            $db_list = mysql_list_dbs($link);
            echo "<pre>\n";
            while ($row = mysql_fetch_array($db_list)) {
                echo $row['Database'] . "\n";
            }
            echo "</pre>\n";
        }
        if ($database) {
        $dbcheck = mysql_select_db("$database");
            if (!$dbcheck) {
                echo mysql_error();
            }else{
                echo "<p>Successfully connected to the database '" . $database . "'</p>\n";
                // Check tables
                $sql = "SHOW TABLES FROM `$database`";
                $result = mysql_query($sql);
                if (mysql_num_rows($result) > 0) {
                    echo "<p>Available tables:</p>\n";
                    echo "<pre>\n";
                    while ($row = mysql_fetch_row($result)) {
                        echo "{$row[0]}\n";
                    }
                    echo "</pre>\n";
                } else {
                    echo "<p>The database '" . $database . "' contains no tables.</p>\n";
                    echo mysql_error();
                }
            }
        }
    }
    ?>

    </div><!-- end #wrapper -->
    </body>
    </html>

參考: [https://ardamis.com/2008/05/26/a-php-script-for-testing-a-mysql-database-connection/][1]

運行SHOW DATABASES並查看information_schema是否在列表中。

但這沒關系吧? 如果您是自托管的,則可以配置它,但是需要它。

將數據庫設置為information_schema並從所選數據庫中運行查詢“顯示表”。 如果您具有讀取訪問權限,則將從該數據庫獲取所有表。 檢查所有查詢的結果。

暫無
暫無

聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.

 
粵ICP備18138465號  © 2020-2024 STACKOOM.COM