The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


WinMySQLadmin 1.1 Store MySQL password in clear text


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Tue, 2 Oct 2001 09:54:57 +0200
From: acz [iSecureLabs] <[email protected]>
To: "Vulnwatch@Vulnwatch. Org" <[email protected]>
Subject: WinMySQLadmin 1.1  Store MySQL password in clear text
Cc: "[email protected]" <[email protected]>

Hi all,

WinMySQLadmin 1.1 store Mysql password in clear text in the file
c:\winnt\my.ini

---<my.ini>---
#This File was made using the WinMySQLadmin 1.1 Tool

[mysqld]
basedir=C:/mysql
datadir=C:/mysql/data

[WinMySQLadmin]
Server=C:/mysql/bin/mysqld-nt.exe
user=admin
password=XXXXX (in clear text)
QueryInterval=30
---<my.ini>---

It can be dangerous if someone can remotly read any file on your NT box with
typicall IIS hole such as
http://packetstormsecurity.org/9905-exploits/ms.iis4.showcode.txt or
anything else...

----
Cabezon AurИlien
http://www.iSecureLabs.com


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру