Re: Cryptocard database
Next message: Jeffrey Leggett: "MIVA Pen test"
Date: Fri, 18 Feb 2005 18:04:56 -0500 (EST)
To: pen-test@securityfocus.com
On Wed, 16 Feb 2005, John Madden wrote:
| Doing an internal pen-test for a company i came across
| a mysql db that contains the Cryptocard tokens
| database (root with no password)
Not only should the mysql be secured, it shouldn't even be accessable from
off the machine that needs to query the database.
IIRC, cadmind actually wanted to talk via the network port only, so we
allow networking for mysql, then firewall off 3306 to only allow
connections from the local system.
-Noel
---Noel Rosenberg
---noel@thesubnet.net
---Sleep Vampire
---"One does not win a mud-slinging fest by getting into the mud;
--- The pigs have the home field advantage."
Next message: Jeffrey Leggett: "MIVA Pen test"
Relevant Pages
- Re: MySQL Database problem (probably already solved in a message, but this is somewhat urgent)
... MySQL server has a database with a table, ... columns, an FSR column, and a password column. ... checked if the supposed arrays that were returned were actually arrays ... (comp.lang.php) - RE: FreeBSD 5.3 MySQL Performance
... versions of Linux and FreeBSD for most tests. ... > popular with the ATA disk drive manufacturers. ... > Many companies have used FreeBSD and MySQL for years and years. ... it is not often that you have such a small database and such a large ... (freebsd-questions) - ANN: Database Designer for MySQL version 1.6 is released
... The new version 1.6 of MicroOLAP Database Designer for MySQL has been ... The secure shell (SSH) tunneling is now implemented in Database ... (borland.public.delphi.thirdpartytools.general) - Re: toolkits or APIs to create a web interface as a frontend to mysql
... I am also *not* looking for a web based full fledged mysql client. ... For simple display of tabulated data the most useful thing is a displaywhich uses 's with absolute coordinates to position text in a box of defined width, formatted to be left, right or center justified, an using a preselected style from a a style sheet. ... As far as the actual database calls go, those are specific to each form, and apart from a little coding so that 'database_open, database_close' exist in the library, taking such things as the database name, user name and password from an included file I find it easiest to simply do the query and iterate through it to display the data requested. ... (comp.os.linux.misc) - Re: PICK OPENDB provides connection in shopping cart startup
... we MIS folks are required to take on tasks that we don't ... developer, nor the database. ... Why do you need MySQL?. ... in size that KTP experienced, evolving to the current 90,000+ sq. ... (comp.databases.pick) |
|