[Cialug] Stupid ?

albus albus at iowaconnect.com
Tue Jul 17 11:00:21 CDT 2007


Well I may not the sharpest tool in the shed( No comment Dave C)
but if ANY allows annonymous access, that sounds like a BAD thing to me.

I think I'll be deleting it then.


----- Original Message ----- 
From: "david l goodrich" <dlg at dsrw.org>
To: "Central Iowa Linux Users Group" <cialug at cialug.org>
Sent: Tuesday, July 17, 2007 10:35 AM
Subject: Re: [Cialug] Stupid ?


> You'll lose anonymous access to your databases.
> 
> I've always deleted it from my server.
> 
> On Tue, July 17, 2007 10:13 am, albus wrote:
>> I'll need remote in the office and some times outside remote.
>> Of which I'll have to setup on my proxy firewall for outside access when
>> needed.
>> Plus I've blocked all port 3306 from anywhere to everything internal 3306.
>> Along with blocking on the server with iptables on top of all that.
>>
>> I take it you add the bind address in my.cnf?
>>
>> But what about deleting that account? What's it going to hose it deleted?
>>
>>
>> ----- Original Message -----
>> From: "Tom Pohl" <tom at tcpconsulting.com>
>> To: "Central Iowa Linux Users Group" <cialug at cialug.org>
>> Sent: Tuesday, July 17, 2007 9:41 AM
>> Subject: Re: [Cialug] Stupid ?
>>
>>
>>> Do you really need to be able to talk to your mysql server remotely?
>>>
>>> If not, I would add --bind-address=127.0.0.1 to your mysql startup
>>> command.
>>>
>>> If so, I would use iptables to limit the source ips to only allow
>>> your machines to talk to port 3306 of your mysql server.
>>>
>>> -Tom
>>>
>>> On Jul 17, 2007, at 9:33 AM, albus wrote:
>>>
>>>> My turn for stupid questions today.
>>>>
>>>> What happens if you delete the ANY user in MySql?
>>>> It isn't tied to any database and the account has no rights but I
>>>> read it can do some things that could casue DoS attack.
>>>> Plus other no, no's
>>>>
>>>> Just wondering cause I'm thinking real hard of deleting it or at least
>>>> put a password on it.
>>>>
>>>> _______________________________________________
>>>> Cialug mailing list
>>>> Cialug at cialug.org
>>>> http://cialug.org/mailman/listinfo/cialug
>>>>
>>>
>>> _______________________________________________
>>> Cialug mailing list
>>> Cialug at cialug.org
>>> http://cialug.org/mailman/listinfo/cialug
>>>
>>>
>>
>> _______________________________________________
>> Cialug mailing list
>> Cialug at cialug.org
>> http://cialug.org/mailman/listinfo/cialug
>>
> 
> 
> _______________________________________________
> Cialug mailing list
> Cialug at cialug.org
> http://cialug.org/mailman/listinfo/cialug
> 
>



More information about the Cialug mailing list