系统环境:Debian 10,Apache2, MySQL(MariaDB),PHP
先看一下web服务器的日志 /var/log/apache2/access.log 中的一部分
80.99.255.243 - - [04/Feb/2022:09:23:35 +0800] "GET /admin/sqladmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:36 +0800] "GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:37 +0800] "GET /phpMyAdmin-4.9.7-english/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:39 +0800] "GET /sql/sqlweb/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:40 +0800] "GET /admin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:41 +0800] "GET /administrator/web/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:42 +0800] "GET /mysql/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:43 +0800] "GET /db/webadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:44 +0800] "GET /phpMyAdmin-4/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:45 +0800] "GET /db/phpMyAdmin3/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:46 +0800] "GET /db/dbweb/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:48 +0800] "GET /phpmyadmin2011/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:49 +0800] "GET /phpMyadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:50 +0800] "GET /admin/sysadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:51 +0800] "GET /pma2015/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:52 +0800] "GET /PMA2017/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:53 +0800] "GET /sql/phpmanager/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:54 +0800] "GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:55 +0800] "GET /db/phpMyAdmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:56 +0800] "GET /phpmyadmin_/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:57 +0800] "GET /sql/phpmyadmin4/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:58 +0800] "GET /sql/webdb/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:23:59 +0800] "GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:01 +0800] "GET /mysql/dbadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:04 +0800] "GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:05 +0800] "GET /phpMyAdmin-4.9.7/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:06 +0800] "GET /sql/sql-admin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:07 +0800] "GET /phpmyadmin2018/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:08 +0800] "GET /phpmyadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:09 +0800] "GET /sqlmanager/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:10 +0800] "GET /phpmyadmin3/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:11 +0800] "GET /sql/sql-admin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:12 +0800] "GET /phpMyAdmin_/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:13 +0800] "GET /mysql/dbadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:15 +0800] "GET /php-myadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:16 +0800] "GET /myadmin/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:17 +0800] "GET /phpMyAdmin1/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:18 +0800] "GET /PMA2015/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
80.99.255.243 - - [04/Feb/2022:09:24:19 +0800] "GET /phpMyAdmin-5.1.1-english/index.php?lang=en HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"
用百度查出 IP:80.99.255.243哪里来的!
可以看到 80.99.255.243 后面的人想进入你的数据库,在短短的44秒里做了39种猜测,希望可以撞对路径,在猜对路径后再会猜用户名和密码;管理MySQL数据库有个常用的web 工具是phpmyadmin,这工具也非常好用,会带来不少方便的工具,经常会被用到,但它的入口也是一个薄弱环节,如果你用默认设置就比较容易被窥视者利用。
下面就修改phpMyAdmin的默认访问路径:
phpmyadmin 默认的入口: http://your-domain-name/phpmyadmin
在目前的环境中(Debian 10,Apache2, MySQL(MariaDB),PHP)
修改 /etc/phpmyadmin/apache.conf 文件中的 Alias /phpmyadmin 部分
Alias /phpmyadmin /usr/share/phpmyadmin
比如: Alias /admin-Proj1 /usr/share/phpmyadmin 在这里命名要用你自己的独特规则才保险,而且自己可以记得住。
重启Apache2就可以用 http://your-domain-name/admin-Proj1 访问你的phpmyadmin,这样就可以大的降低被攻击的风险,提高数据安全性。
下面是用默认路径被窥视者尝试破解数据库密码的日志:
185.170.210.7 - - [10/Feb/2022:14:49:46 +0800] "GET /index.php HTTP/1.1" 404 492 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:47 +0800] "GET /phpmyadmin/index.php HTTP/1.1" 200 12352 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:47 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:47 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:48 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:49 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:14:49:50 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
......
185.170.210.7 - - [10/Feb/2022:15:26:20 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:15:26:21 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:15:26:22 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:15:26:22 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
185.170.210.7 - - [10/Feb/2022:15:26:23 +0800] "POST /phpmyadmin/index.php HTTP/1.1" 200 12842 "http://49.100.100.100/phpmyadmin/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
在37分钟里被做了三千多次破解数据库尝试,你可以想象吗?是否应该马上修改默认路径?
下面是修改路径名以后,自己常规访问以后的日志
101.100.100.100 - - [20/Feb/2022:15:19:58 +0800] "GET /PhpmyAdmin/ HTTP/1.1" 200 5085 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/themes/pmahomme/jquery/jquery-ui-1.11.4.css HTTP/1.1" 200 8431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/codemirror/lib/codemirror.css?v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 2746 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/codemirror/addon/hint/show-hint.css?v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 672 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/codemirror/addon/lint/lint.css?v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 1623 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/get_scripts.js.php?scripts%5B%5D=jquery/jquery-2.1.4.min.js&scripts%5B%5D=sprintf.js&scripts%5B%5D=ajax.js&scripts%5B%5D=keyhandler.js&scripts%5B%5D=jquery/jquery-ui-1.11.4.min.js&scripts%5B%5D=jquery/jquery.cookie.js&scripts%5B%5D=jquery/jquery.mousewheel.js&scripts%5B%5D=jquery/jquery.event.drag-2.2.js&scripts%5B%5D=jquery/jquery-ui-timepicker-addon.js&scripts%5B%5D=jquery/jquery.ba-hashchange-1.3.js&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 134593 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/get_scripts.js.php?scripts%5B%5D=console.js&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 11144 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&collation_connection=utf8mb4_unicode_ci&token=85a11df4e3b20053fd2424ff906e2c9f&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 871 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/get_scripts.js.php?scripts%5B%5D=indexes.js&scripts%5B%5D=common.js&scripts%5B%5D=page_settings.js&scripts%5B%5D=codemirror/lib/codemirror.js&scripts%5B%5D=codemirror/mode/sql/sql.js&scripts%5B%5D=codemirror/addon/runmode/runmode.js&scripts%5B%5D=codemirror/addon/hint/show-hint.js&scripts%5B%5D=codemirror/addon/hint/sql-hint.js&scripts%5B%5D=codemirror/addon/lint/lint.js&scripts%5B%5D=codemirror/addon/lint/sql-lint.js&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 119392 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/get_scripts.js.php?scripts%5B%5D=jquery/jquery.debounce-1.0.5.js&scripts%5B%5D=menu-resizer.js&scripts%5B%5D=cross_framing_protection.js&scripts%5B%5D=rte.js&scripts%5B%5D=tracekit/tracekit.js&scripts%5B%5D=error_report.js&scripts%5B%5D=config.js&scripts%5B%5D=doclinks.js&scripts%5B%5D=functions.js&scripts%5B%5D=navigation.js&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 82971 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/phpmyadmin.css.php?nocache=4437063584ltr HTTP/1.1" 200 20491 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&collation_connection=utf8mb4_unicode_ci&token=85a11df4e3b20053fd2424ff906e2c9f&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9821 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:19:59 +0800] "GET /PhpmyAdmin/js/get_image.js.php?theme=pmahomme&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 2230 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:04 +0800] "GET /PhpmyAdmin/themes/dot.gif HTTP/1.1" 200 325 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:04 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/logo_right.png HTTP/1.1" 200 4834 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:04 +0800] "GET /PhpmyAdmin/themes/pmahomme/css/printview.css?v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 1323 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:04 +0800] "GET /PhpmyAdmin/favicon.ico HTTP/1.1" 200 22788 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:04 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/sprites.png?v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 47020 "http://49.100.100.100/PhpmyAdmin/phpmyadmin.css.php?nocache=4437063584ltr" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:09 +0800] "GET /PhpmyAdmin HTTP/1.1" 301 594 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:09 +0800] "GET /PhpmyAdmin/ HTTP/1.1" 200 4408 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:10 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&token=221f6af47f68372f0949e40396483df6&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 872 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:20:10 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&token=221f6af47f68372f0949e40396483df6&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9822 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
127.0.0.1 - - [20/Feb/2022:15:20:15 +0800] "OPTIONS * HTTP/1.0" 200 126 "-" "Apache/2.4.25 (Debian) mod_fcgid/2.3.9 OpenSSL/1.0.2u (internal dummy connection)"
101.100.100.100 - - [20/Feb/2022:15:31:02 +0800] "GET /PhpmyAdmin/ HTTP/1.1" 200 4407 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:31:02 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&token=3b222020732495d7cc33aadc9449ade9&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 871 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:31:02 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&token=3b222020732495d7cc33aadc9449ade9&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9822 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:32:33 +0800] "POST /PhpmyAdmin/index.php HTTP/1.1" 200 4611 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:32:33 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&token=347c632bcaba82f377d6e12f42ffa89a&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 871 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:32:33 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&token=347c632bcaba82f377d6e12f42ffa89a&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9822 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:14 +0800] "POST /PhpmyAdmin/index.php HTTP/1.1" 302 1113 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:14 +0800] "GET /PhpmyAdmin/index.php?token=859abfea9d696924dfb32ae2e13c103f HTTP/1.1" 200 17889 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/phpmyadmin.css.php?nocache=6082578778ltr HTTP/1.1" 200 20491 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&token=859abfea9d696924dfb32ae2e13c103f&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 871 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&token=859abfea9d696924dfb32ae2e13c103f&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9822 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/logo_left.png HTTP/1.1" 200 2519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/ajax_clock_small.gif HTTP/1.1" 200 2096 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/b_plugin.png HTTP/1.1" 200 876 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/s_collapseall.png HTTP/1.1" 200 454 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/left_nav_bg.png HTTP/1.1" 200 541 "http://49.100.100.100/PhpmyAdmin/phpmyadmin.css.php?nocache=6082578778ltr" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "POST /PhpmyAdmin/navigation.php?ajax_request=1&token=859abfea9d696924dfb32ae2e13c103f HTTP/1.1" 200 4554 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:15 +0800] "POST /PhpmyAdmin/db_structure.php?ajax_request=1&favorite_table=1&sync_favorite_tables=1&token=859abfea9d696924dfb32ae2e13c103f HTTP/1.1" 200 1210 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
127.0.0.1 - - [20/Feb/2022:15:33:20 +0800] "OPTIONS * HTTP/1.0" 200 126 "-" "Apache/2.4.25 (Debian) mod_fcgid/2.3.9 OpenSSL/1.0.2u (internal dummy connection)"
101.100.100.100 - - [20/Feb/2022:15:33:26 +0800] "GET /PhpmyAdmin/db_structure.php?server=1&db=crm71018&token=859abfea9d696924dfb32ae2e13c103f&ajax_request=true&ajax_page_request=true&_nocache=1645515204512648560 HTTP/1.1" 200 40971 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:31 +0800] "GET /PhpmyAdmin/themes/pmahomme/img/arrow_ltr.png HTTP/1.1" 200 422 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:31 +0800] "GET /PhpmyAdmin/navigation.php?ajax_request=1&token=859abfea9d696924dfb32ae2e13c103f&aPath=cm9vdA%3D%3D.Y3JtNzEwMTg%3D&vPath=cm9vdA%3D%3D.Y3JtNzEwMTg%3D&pos=0&pos2_name=&pos2_value=&searchClause=&searchClause2=&_nocache=1645515208849153136 HTTP/1.1" 200 5391 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:31 +0800] "GET /PhpmyAdmin/js/get_scripts.js.php?scripts%5B%5D=db_structure.js&scripts%5B%5D=tbl_change.js&call_done=1&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 11108 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:43 +0800] "GET /PhpmyAdmin/logout.php?db=&token=859abfea9d696924dfb32ae2e13c103f HTTP/1.1" 302 13908 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:44 +0800] "GET /PhpmyAdmin/index.php HTTP/1.1" 200 4578 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:44 +0800] "GET /PhpmyAdmin/js/whitelist.php?lang=zh_CN&db=&token=c2d9fc1cf465397035d3ac42b912a488&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 871 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
101.100.100.100 - - [20/Feb/2022:15:33:44 +0800] "GET /PhpmyAdmin/js/messages.php?lang=zh_CN&db=&token=c2d9fc1cf465397035d3ac42b912a488&v=4.6.6deb4%2Bdeb9u2 HTTP/1.1" 200 9822 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0"
不同的环境中设置的路径和文件会有所不同,更多环境详见链接
关闭MYSQL数据库默认的端口3306,MySQL客户端通过SSH端口22访问数据库
|