赞
踩
sqli-labs是一个SQL注入测试的渗透环境
在搭建之前我们需要有lamp的环境
安装Apache的服务器
yum install httpd
然后启动Apache
service httpd start
查看Apache状态
service httpd status
设置httpd在运行级别为2、3、4、5的情况下都是on的状态(如果发现测试php时网页显示源代码,尝试把此代码来一遍)
chkconfig --level 2345 httpd on
firewall-cmd --permanent --zone=public --add-service=httpd
安装MySQL
//因为最新版的linux系统开始,默认的是Mariadb
而不是mysql~//
检查系统是否装有mysql,返回空值则说明没有安装
rpm -qa |grep mysql
//yum install虽然可执行,但是只是用来更新Mariadb的//
wget
http://repo.mysql.com/mysql-community-release-el7-5.noarch.rpm
安装mysql-community-release-el7-5.noarch.rpm
rpm -ivh mysql-community-release-el7-5.noarch.rpm
安装Mysql
yum install mysql-server
安装完成后再次查看MySQL
rpm -qa | grep mysql
如果报错内容含有
Error: Package: mysql-community-libs-5.6.35-2.el7.x86_64 (mysql56-community) Requires: libc.so.6(GLIBC_2.17)(64bit) Error: Package: mysql-community-server-5.6.35-2.el7.x86_64 (mysql56-community) Requires: libc.so.6(GLIBC_2.17)(64bit) Error: Package: mysql-community-server-5.6.35-2.el7.x86_64 (mysql56-community) Requires: systemd Error: Package: mysql-community-server-5.6.35-2.el7.x86_64 (mysql56-community) Requires: libstdc++.so.6(GLIBCXX_3.4.15)(64bit) Error: Package: mysql-community-client-5.6.35-2.el7.x86_64 (mysql56-community) Requires: libc.so.6(GLIBC_2.17)(64bit) You could try using --skip-broken to work around the problem You could try running: rpm -Va --nofiles --nodigest
解决:
yum install glibc.i686
yum list libstdc++*
重置密码
首先登陆
mysql -u root
登录时有可能报这样的错:
ERROR 2002 (HY000): Can’t connect to local MySQL server through socket ‘/var/lib/mysql/mysql.sock’ (2)
原因是/var/lib/mysql的访问权限问题。下面的命令把/var/lib/mysql的拥有者改为当前用户
chown -R root:root /var/lib/mysql
重启服务
service mysqld restart
登陆MySQL重置密码
mysql -u root
mysql > use mysql;
mysql > update user set password=password(‘123456’) where user=‘root’;
mysql > exit;
重启Mysq服务
service mysqld restart
安装PHP
yum install php.x86_64 php-mysql.x86_64 php-pear php-pear-DB php-gb
下载sqli-labs
https://github.com/Audi-1/sqli-labs
完成后解压放到网站的目录里,小白的是在/home/www/htdocs/下。然后打开文件sqli-labs/sql-connections/db-creds.ins,把IP地址和数据库密码修改成正确即可访问。
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。