Full Disclosure mailing list archives

Re: User bypass privs for Mysql??


From: Ben Nelson <lists () venom600 org>
Date: Tue, 18 May 2004 10:33:03 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Esler, Joel - Contractor wrote:
| I did not have the grant priv, I had select, insert on mysql db.  (I did
| log in as a different user --i.e. not root)  Using MysqlCC I changed the
| Grant field from N to Y, and then could grand myself all privs to every
| database.
|
| Of course, I did have select, insert on mysql..  probably why huh?
|

Yes.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAqjq/3cL8qXKvzcwRAu0HAKCsmiagThnVd51jO8yBungP5qpnXQCglELN
fPhi9LqqqhcSGIx7OCQeE+c=
=tRpm
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: