Re: MySQL Security Risk?

From: Brian C. Lane (bcl_at_marvin.home)
Date: 08/27/04

  • Next message: Bob Holding: "How To Log Password Change"
    Date: Fri, 27 Aug 2004 03:02:17 -0000
    
    

    In article <eGBWc.104990$r4.2688081@news-reader.eresmas.com>, Jose Maria Lopez Hernandez wrote:
    > Neil wrote:
    >> Hi All,
    >>
    >> I'd like to install MySQL and PHP onto my server that's hosted in a POP on
    >> the internet. No i have no firewall on tha machine, but i only have the
    >> SSH, FTP (chrooted, no real users) and APACHE services running. I trust
    >> these services (rightly or wrongly).
    >>
    >> Now MySQL has been around for ages and i was wondering if it is secure
    >> enough to run on an open server? I understand that you can limit access to
    >> users at specific IP addresses, but is this service still vunerable to
    >> attack?
    >>
    >> I'd greatly appreciate your views.
    >>
    >> Neil
    >>
    >>
    >>
    >
    > In my penetration tests with nessus and some exploits it looks pretty
    > strong. You should be more worried about Apache, that it's much more
    > problematic. At least it's my point of view.
    >
    >

    MySQL has had some pretty serious security problems in the past (I
    seem to remember one where the password checking code used the length of
    the supplied password to control the check...)

    I would use iptables to block external access to port 3306 and if any
    external apps need to access it you can setup a ssh tunnel from the remote
    machine so that the connection is protected.

    Brian

    -- 
    ---[Office 73.3F]--[Fridge 38.6F]---[Fozzy 93.5F]--[Coaster 73.2F]---
    Linux Software Developer                     http://www.brianlane.com
    

  • Next message: Bob Holding: "How To Log Password Change"

    Relevant Pages

    • RE: MySQL/PHPMyAdmin on FC3 Connection Problem
      ... // You can disable a server config entry by setting host to ''. ... MySQL server ... MySQL control user settings ... table to describe the display fields ...
      (Fedora)
    • Re: KDE is now broken (Fwd: Heads-up: KDE4 hitting testing tonight (UTC) )
      ... don't want to run an akonadi server either, ... KDE 4.0 was available. ... kmail) and I do not have a mysql server installed. ...
      (Debian-User)
    • Re: Using Access for web application?
      ... Any suggestions as to which newsgroup would be more ... The server that the web app will use in this case, ... > which technology you will decide to use as the Web server (Linux or Windows) ... Instead MySQL is being ...
      (microsoft.public.access.dataaccess.pages)
    • [UNIX] phpMyAdmin PHP Code Injection (left.php)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... phpMyAdmin is "web-based MySQL ... does not prevent a malicious user from altering the servers configuration ... server configurations to the list of servers configuration by adding ...
      (Securiteam)
    • Re: KDE is now broken (Fwd: Heads-up: KDE4 hitting testing tonight (UTC) )
      ... don't want to run an akonadi server either, ... doesn't ask if I want to use a mysql server on another host. ... Not if the file format was public. ... There seems to be too much windoze thinking entering Debian: ...
      (Debian-User)