MySQL Null Root Password Weak Default Configuration Vulnerability
BID:5503
Info
MySQL Null Root Password Weak Default Configuration Vulnerability
| Bugtraq ID: | 5503 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Aug 19 2002 12:00AM |
| Credit: | Published by Mike Bommarito <[email protected]>. |
| Vulnerable: |
MySQL AB MySQL 3.23.52 MySQL AB MySQL 3.23.51 MySQL AB MySQL 3.23.50 MySQL AB MySQL 3.23.49 MySQL AB MySQL 3.23.48 MySQL AB MySQL 3.23.47 MySQL AB MySQL 3.23.46 MySQL AB MySQL 3.23.45 MySQL AB MySQL 3.23.44 MySQL AB MySQL 3.23.43 MySQL AB MySQL 3.23.42 MySQL AB MySQL 3.23.41 MySQL AB MySQL 3.23.40 MySQL AB MySQL 3.23.39 MySQL AB MySQL 3.23.38 MySQL AB MySQL 3.23.37 MySQL AB MySQL 3.23.36 MySQL AB MySQL 3.23.34 MySQL AB MySQL 3.23.31 MySQL AB MySQL 3.23.30 MySQL AB MySQL 3.23.29 MySQL AB MySQL 3.23.28 MySQL AB MySQL 3.23.27 MySQL AB MySQL 3.23.26 MySQL AB MySQL 3.23.25 MySQL AB MySQL 3.23.24 MySQL AB MySQL 3.23.23 MySQL AB MySQL 3.23.10 MySQL AB MySQL 3.23.9 MySQL AB MySQL 3.23.8 MySQL AB MySQL 3.23.5 MySQL AB MySQL 3.23.4 MySQL AB MySQL 3.23.3 MySQL AB MySQL 3.23.2 MySQL AB MySQL 3.22.32 MySQL AB MySQL 3.22.30 MySQL AB MySQL 3.22.29 MySQL AB MySQL 3.22.28 MySQL AB MySQL 3.22.27 MySQL AB MySQL 3.22.26 MySQL AB MySQL 3.20.32 a |
| Not Vulnerable: | |
Discussion
MySQL Null Root Password Weak Default Configuration Vulnerability
MySQL is is an open source relational database project, and is available for a number of operating systems, including Microsoft Windows.
A weak default configuration problem has been reported in the Windows binary release of MySQL. Reportedly, the root user of the database is defined with no password, and granted login privileges from any host.
This issue has been reported in the Windows binary release of MySQL. Other versions may share this default configuration, this has not however been confirmed.
MySQL is is an open source relational database project, and is available for a number of operating systems, including Microsoft Windows.
A weak default configuration problem has been reported in the Windows binary release of MySQL. Reportedly, the root user of the database is defined with no password, and granted login privileges from any host.
This issue has been reported in the Windows binary release of MySQL. Other versions may share this default configuration, this has not however been confirmed.
Exploit / POC
MySQL Null Root Password Weak Default Configuration Vulnerability
No exploit is required. Exploits have, however, been provided by Mike Bommarito <[email protected]> and st0ic <[email protected]>:
No exploit is required. Exploits have, however, been provided by Mike Bommarito <[email protected]> and st0ic <[email protected]>:
Solution / Fix
MySQL Null Root Password Weak Default Configuration Vulnerability
Solution:
Administrators should either disable the default account, or supply a strong password. The following SQL command is supplied by Mike Bommarito <[email protected]>:
DELETE FROM mysql.user;
GRANT ALL PRIVILEGES ON *.* TO user@localhost
IDENTIFIED BY 'password' WITH GRANT OPTION;
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Administrators should either disable the default account, or supply a strong password. The following SQL command is supplied by Mike Bommarito <[email protected]>:
DELETE FROM mysql.user;
GRANT ALL PRIVILEGES ON *.* TO user@localhost
IDENTIFIED BY 'password' WITH GRANT OPTION;
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MySQL Null Root Password Weak Default Configuration Vulnerability
References:
References:
- MySQL Homepage (Oracle)