資料庫被勒索只能跑路?先等等!
今天早晨,打開資料庫一看,保存的數據全不見了,只剩下一個叫PLEASE_READ_ME_VVV的資料庫。
裡面寫著
To recover your lost Database and avoid leaking it: Send us 0.045 Bitcoin (BTC) to our Bitcoin address 1McksxpysJGSG9a9zHvan5f8Y1nfpDbVYF and contact us by Email with your Server IP or Domain name and a Proof of Payment. Your Database is downloaded and backed up on our servers. Backups that we have right now: *. Any email without your server IP Address or Domain Name and a Proof of Payment together will be ignored. If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
翻譯過來就是:
要恢復丟失的資料庫並避免泄漏:請將0.045比特幣(BTC)發送到我們的比特幣地址1Mcksxpysjgsg9a9zhvan5f8y1nfpdbvyf,並通過電子郵件與您的伺服器IP或域名和付款證明聯繫。您的資料庫已下載並備份到我們的伺服器上。我們現在擁有的備份:*。任何沒有您的伺服器IP地址或域名和付款證明一起的電子郵件都將被忽略。如果我們在未來10天內沒有收到您的付款,我們將公開您的資料庫或使用它們。
被勒索了。
第一步,打開谷歌尋找解決辦法。看到這篇博文,遇到了同樣的問題。
資料庫被人勒索比特幣慘遭刪庫 https://www.printf520.com/single.html?id=53
以下內容,針對具體情況進行進一步處理。
第二步,查看自已是否打開了mysql的binlog
SHOW VARIABLES LIKE log_bin%;
+---------------------------------+---------------------------------------+
| Variable_name | Value |
+---------------------------------+---------------------------------------+
| log_bin | ON |
| log_bin_basename | /usr/local/var/mysql/mysql-bin |
| log_bin_index | /usr/local/var/mysql/mysql-bin.index |
| log_bin_trust_function_creators | OFF |
| log_bin_use_v1_row_events | OFF |
| sql_log_bin | ON |
+---------------------------------+---------------------------------------+
6 rows in set (0.00 sec)
log_bin是ON說明mysql是開啟了binlog的,找到了binlog的位置,在
/usr/local/var/mysql/mysql-bin
於是
cd var/lib/mysql