View Single Post
Old 06-21-2010, 08:01 AM  
gleem
Confirmed User
 
gleem's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
Quote:
Originally Posted by raymor View Post
Most any PHP script will provide enough access, and by default no password is required to log
in to the database. This due to a widely held misconception about how the default account works.
So default MySQL, not secured by someone who knows what they are doing + any popular PHP script = DB publicly available.




Certainly DB access to remote servers (tcp) should be disabled if possible.
Care to expand further on the MySQL default account?
__________________




Contact me: \\// E: webmaster /at/ unprofessional.com
gleem is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote