Re: load data local ... security issue

2002-02-06 Thread David Phillips
But you could already read any file that the web server can read, if you can execute scripts which are run as the webserver. Only way to prevent that is suEXEC. How is this specific to MySQL? > 1) Webserver must be able to read HTML files of every WebUsers > 2) MySQL functions are called with u

Re: what is the security issue with dynamic format?

2001-10-02 Thread Dan Nelson
In the last episode (Oct 02), denis mercier said: > I am presently going over the mysql documentation to get familiar > with it, It runs great on my development server (linux RH7.1 > kernel=2.4.2-2 resin application server), I am in the process of > optimizing and testing , I am using blob datatyp

what is the security issue with dynamic format?

2001-10-02 Thread denis mercier
hi I am presently going over the mysql documentation to get familiar with it, It runs great on my development server (linux RH7.1 kernel=2.4.2-2 resin application server), I am in the process of optimizing and testing , I am using blob datatype in my main table, I understand why a fixed-size form

Re: SECURITY issue in remote tcp/ip connecting?

2001-01-20 Thread Tõnu Samuel
Derek Sivers wrote: > > > > Any measures I could take (like SSH) to encrypt the transaction? > >Use CIPE tunnel. You can find it: > >http://sites.inka.de/sites/bigred/devel/cipe.html > > Is this anything like ipsec? > http://www.openbsd.org/faq/faq13.html > (I'm using OpenBSD.) > > Or, rather,

Re: SECURITY issue in remote tcp/ip connecting?

2001-01-19 Thread Derek Sivers
> > Any measures I could take (like SSH) to encrypt the transaction? >Use CIPE tunnel. You can find it: >http://sites.inka.de/sites/bigred/devel/cipe.html Is this anything like ipsec? http://www.openbsd.org/faq/faq13.html (I'm using OpenBSD.) Or, rather, could I use ipsec for this same thing a

Re: SECURITY issue in remote tcp/ip connecting?

2001-01-19 Thread Tõnu Samuel
Derek Sivers wrote: > searched the lists & books & found no mention of this: > > Are there any security issues in doing lots of remote-connecting (TCP/IP) > to my MySQL database server? Anything can be broken with this. MySQL limits this by amount of max_connections but if someone else occupi

SECURITY issue in remote tcp/ip connecting?

2001-01-19 Thread Derek Sivers
searched the lists & books & found no mention of this: Are there any security issues in doing lots of remote-connecting (TCP/IP) to my MySQL database server? (My Apache/PHP is on a different webserver from the MySQL server. And sometimes across the country.) Won't that password be somehow sn

Re: Security issue

2001-01-18 Thread Sergei Golubchik
Hi! On Jan 18, Nicolas GREGOIRE wrote: > Hi, > > Still not any info about the buffer-overflow discovered last week ? > Shouldn't be fixed at the beginning of the week ? > > Please, dear MySQL team, give us info !! > > Regards, > Nicob Fixed in latest release (3.23.31). Regards, Sergei -- My

Security issue

2001-01-18 Thread Nicolas GREGOIRE
Hi, Still not any info about the buffer-overflow discovered last week ? Shouldn't be fixed at the beginning of the week ? Please, dear MySQL team, give us info !! Regards, Nicob - Before posting, please check: http://www.my

Re: mysql security issue

2001-01-15 Thread Sergei Golubchik
Hi! On Jan 15, Nicolas GREGOIRE wrote: > > > Sergei Golubchik a Ucrit : > > > > Hi! > > > > On Jan 12, JoUo Gouveia wrote: > > > Hi, > > > > > > I believe i've found a problem in MySql. Here are some test's i've made in > > > 3.22.27 x86( also tested on v3.22.32 - latest stable, although i didn't

Re : mysql security issue, overflow

2001-01-15 Thread Nicolas GREGOIRE
Sergei Golubchik a écrit : > > Hi! > > On Jan 12, João Gouveia wrote: > > Hi, > > > > I believe i've found a problem in MySql. Here are some test's i've made in > > 3.22.27 x86( also tested on v3.22.32 - latest stable, although i didn't > > debug it, just tested to see if crashes ). > > Confirm

Re: mysql security issue, overflow

2001-01-12 Thread Sergei Golubchik
Hi! On Jan 12, João Gouveia wrote: > Hi, > > I believe i've found a problem in MySql. Here are some test's i've made in > 3.22.27 x86( also tested on v3.22.32 - latest stable, although i didn't > debug it, just tested to see if crashes ). Confirmed up to latest 3.23 This will be fixed ASAP! Th

mysql security issue, overflow

2001-01-12 Thread João Gouveia
Hi, I believe i've found a problem in MySql. Here are some test's i've made in 3.22.27 x86( also tested on v3.22.32 - latest stable, although i didn't debug it, just tested to see if crashes ). On one terminal: spike:/var/mysql # /sbin/init.d/mysql start Starting service MySQL. Starting mysqld