dpnof28482 2016-10-30 13:50
浏览 50
已采纳

是否可以通过知道PHP中的用户名和密码(仅限)来破解我的数据库[关闭]

Is it possible for someone to hack a MySQL database by knowing (only) the username and the password for my database.

There is no phpMyAdmin to login from it and there is no way to do any SQL injection in the website (because I'm using Laravel).

  • 写回答

1条回答 默认 最新

  • dongqie8661 2016-10-30 16:24
    关注

    Your question is quite similar to "Is it possible to break into my house with my door key?"

    It depends on few things:

    1. Which IP is your MySQL listening to? In your MySQL Config File bind-address, find the value.
    2. For that specific username, did you enabled remote access for that user in MySQL?
    3. Any Firewall rules to restrict remote MySQL connections?

    By the way, using Laravel or any other frameworks does NOT guarantee anything on protecting from SQL injection. People can easily write a SQL injection vulnerable web page under any framework if they want.

    You should:

    • Implement your database related code properly and follow the instruction in the documentation.
    • Set your MySQL users and their privilege in the right way.
    • Do not expose your database to the public is recommended.

    Last thing for your update, if you want to share your database with others. Not a big problem if you set the privilege correctly.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥100 set_link_state
  • ¥15 虚幻5 UE美术毛发渲染
  • ¥15 CVRP 图论 物流运输优化
  • ¥15 Tableau online 嵌入ppt失败
  • ¥100 支付宝网页转账系统不识别账号
  • ¥15 基于单片机的靶位控制系统
  • ¥15 真我手机蓝牙传输进度消息被关闭了,怎么打开?(关键词-消息通知)
  • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
  • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
  • ¥15 手机接入宽带网线,如何释放宽带全部速度