Bugtraq mailing list archives
WinMySQLadmin 1.1 Store MySQL password in clear text
From: "acz [iSecureLabs]" <aurelien.cabezon () iSecureLabs com>
Date: Tue, 2 Oct 2001 09:54:57 +0200
Hi all, WinMySQLadmin 1.1 store Mysql password in clear text in the file c:\winnt\my.ini ---<my.ini>--- #This File was made using the WinMySQLadmin 1.1 Tool [mysqld] basedir=C:/mysql datadir=C:/mysql/data [WinMySQLadmin] Server=C:/mysql/bin/mysqld-nt.exe user=admin password=XXXXX (in clear text) QueryInterval=30 ---<my.ini>--- It can be dangerous if someone can remotly read any file on your NT box with typicall IIS hole such as http://packetstormsecurity.org/9905-exploits/ms.iis4.showcode.txt or anything else... ---- Cabezon Aurélien http://www.iSecureLabs.com
Current thread:
- WinMySQLadmin 1.1 Store MySQL password in clear text acz [iSecureLabs] (Oct 02)