Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Ndibhala kakhulu malunga nokufunyanwa kwedatha efikeleleke ngokukhululekileyo phantse kuwo onke amazwe ehlabathi, kodwa akukho phantse iindaba malunga nokugcinwa kwedatha yaseRashiya eshiywe kwindawo yoluntu. Nangona kutshanje wabhala malunga "nesandla se-Kremlin," apho umphandi waseDatshi wayesoyika ukuyifumana ngaphezu kwe-2000 yedatha evulekileyo.

Kunokubakho ukungaqondi kakuhle ukuba yonke into ilungile eRashiya kwaye abanini beeprojekthi ezinkulu zaseRashiya ze-intanethi bathatha indlela enoxanduva lokugcina idatha yomsebenzisi. Ndikhawuleza ukuyichaza le ntsomi ndisebenzisa lo mzekelo.

Inkonzo yezonyango yaseRashiya kwi-intanethi ye-DOC + ngokucacileyo ikwazile ukushiya i-ClickHouse database kunye neendawo zokungena ezifumaneka esidlangalaleni. Ngelishwa, iilog zijongeka zineenkcukacha kangangokuba idatha yobuqu yabasebenzi, amaqabane kunye nabathengi benkonzo ibinokuvuza.

Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Izinto zokuqala kuqala ...

Дисклеймер: вся информация ниже публикуется исключительно в образовательных целях. Автор не получал доступа к персональным данным третьих лиц и компаний. Скриншоты взяты либо из открытых источников, либо были предоставлены автору анонимными доброжелателями.

Ndikunye nam, njengomnini wetshaneli yeTelegram "Ulwazi luyavuza", Umfundi wesitishi onqwenela ukungaziwa igama lakhe uye wanxibelelana kwaye waxela ngokoqobo oku kulandelayo:

Iseva yeClickHouse evulekileyo yafunyanwa kwi-Intanethi, eyenkampani doc+. Idilesi ye-IP yomncedisi ihambelana nedilesi ye-IP apho idomeyini ye-docplus.ru iqwalaselwe.

Isuka kwiWikipedia: I-DOC + (iNew Medicine LLC) yinkampani yezonyango yaseRashiya enikezela ngeenkonzo kwintsimi ye-telemedicine, ukubiza ugqirha ekhaya, ukugcinwa kunye nokusebenza. idatha yobuqu yezonyango. Inkampani ifumene utyalo-mali kwiYandex.

Ukuqwalasela ulwazi oluqokelelweyo, i-ClickHouse database yayifikeleleke ngokukhululekileyo, kwaye nabani na, eyazi idilesi ye-IP, unokufumana idatha kuyo. Le datha ibonakale ngathi ziilog zofikelelo lwenkonzo.

Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Njengoko ubona kumfanekiso ongentla, ukongeza kwi-www.docplus.ru iseva yewebhu kunye ne-ClickHouse iseva (port 9000), i-database ye-MongoDB ixhonywe ngokubanzi kwidilesi ye-IP efanayo (apho, ngokucacileyo, akukho nto. umdla).

Ngokokwazi kwam, i-injini yokukhangela ye-Shodan.io yasetyenziselwa ukufumanisa iseva yeClickHouse (malunga Abaphandi bafumana njani oovimba beenkcukacha ezivulekileyo Ndabhala ngokwahlukileyo) ngokubambisana neskripthi esikhethekileyo Cofa ezantsi, ekhangele idatabase efunyenweyo ngenxa yokunqongophala koqinisekiso kwaye idwelise zonke iitafile zayo. Ngelo xesha kwakubonakala ngathi kukho abangama-474.

Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Ukusuka kumaxwebhu siyazi ukuba ngokungagqibekanga, iseva yeClickHouse imamele iHTTP kwi-port 8123. Ke ngoko, ukubona okuqulathwe kwiitafile, kwanele ukwenza into efana nalo mbuzo weSQL:

http://[IP-адрес]:8123?query=SELECT * FROM [название таблицы]

Njengesiphumo sokwenza isicelo, yintoni enokuthi ibuyiswe yile iboniswe kumfanekiso wekhusi ongezantsi:

Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Ukusuka kumfanekiso wekhusi kucacile ukuba ulwazi olukwintsimi IINTLOKO iqulethe idatha malunga nendawo (ubude kunye nobude) bomsebenzisi, idilesi yakhe ye-IP, ulwazi malunga nesixhobo aqhagamshele kuso inkonzo, inguqulo ye-OS, njl.

Ukuba kwenzekile ukuba umntu aguqule kancinane umbuzo weSQL, umzekelo, ngolu hlobo:

http://[IP-адрес]:8123?query=SELECT * FROM [название таблицы] WHERE REQUEST LIKE ‘%25Profiles%25’

ke into efana nedatha yobuqu yabasebenzi inokubuyiselwa, eyile: igama elipheleleyo, umhla wokuzalwa, isini, inombolo yesazisi serhafu, ubhaliso kunye needilesi zokwenyani zendawo yokuhlala, iinombolo zomnxeba, izikhundla, idilesi ye-imeyile nokunye okuninzi:

Indlela idatha yobuqu yezigulane kunye noogqirha inokuthi yonakaliswe ngenxa ye-ClickHouse database evulekile

Lonke olu lwazi luvela kwiscreenshot apha ngasentla lufana kakhulu nedatha ye-HR evela kwi-1C: Enterprise 8.3.

Ukujonga ngakumbi kwiparameter API_USER_TOKEN unokucinga ukuba lo luphawu "lokusebenza" onokuthi ngalo wenze izenzo ezahlukeneyo egameni lomsebenzisi, kubandakanya nokufumana idatha yakhe yobuqu. Kodwa ke andinakuyithetha le nto.

Okwangoku akukho lwazi lokuba iseva yeClickHouse isafumaneka ngokukhululekileyo kwidilesi ye-IP efanayo.

umthombo: www.habr.com

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster