Full Disclosure mailing list archives
Re: User bypass privs for Mysql??
From: Michael Gargiullo <mgargiullo () warpdrive net>
Date: Tue, 18 May 2004 12:34:42 -0400
On Tue, 2004-05-18 at 10:02, Esler, Joel - Contractor wrote:
Not having any grant permissions. I went into the mysql/user table and edited the Grant from N to Y. Logged out and logged back in, and I had full privs including Grant. I shouldn't be able to do this... Joel
but does your user have update permissions on either *.* or mysql.* etc... If as the root mysql user you give update permissions to the mysql.users table to a user, they can update themselves to what ever they want. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- User bypass privs for Mysql?? Esler, Joel - Contractor (May 18)
- Re: User bypass privs for Mysql?? James Bliss (May 18)
- Re: User bypass privs for Mysql?? Ben Nelson (May 18)
- RE: User bypass privs for Mysql?? Remko Lodder (May 18)
- Re: User bypass privs for Mysql?? Michael Gargiullo (May 18)
- <Possible follow-ups>
- RE: User bypass privs for Mysql?? Esler, Joel - Contractor (May 18)
- Re: User bypass privs for Mysql?? Maarten (May 18)
- Re: User bypass privs for Mysql?? Ben Nelson (May 18)
- RE: User bypass privs for Mysql?? Esler, Joel - Contractor (May 18)
- Re[2]: User bypass privs for Mysql?? npguy (May 18)