MySQL security and Windows
| From: | G Schneider | Date: | Wed, 07 Nov 2001 14:24:13 +0000 |
| Subject: | MySQL security and Windows | ||
| Groups: | php.windows | ||
| Request: | Send a blank email to php-windows+get-10257@lists.php.net to get a copy of this message | ||
Hi,
I've posted to this group before about this, but I'll give it a second shot:
I represent a small webhost, running a normal M$ Windows2000 IIS5 server.
Everything works fine. But, the users of our MySQL service can somehow
create any number of databases that they like, *even though* we have set it
up so users *can't* do that.
For example,
we'll create a imaginary user called 'Jack' and give him the rights to edit
a database called 'JacksDB' using the following SQL command:
GRANT ALL PRIVILEGES ON JacksDB.* TO Jack@localhost IDENTIFIED BY
'password';
After that's done, our user Jack has been created. But only with the rights
to edit his own database (JacksDB).
In fact, our friend Jack is listed in the mysql.user database as having no
privileges ('N'). And under the mysql.db database, our user Jack is listed
as having every privilege ('Y') on the database called JacksDB.* all except
the Grant_priv.
So this is all well and good, it's how it's supposed to be.
We'll even do a FLUSH PRIVILEGES to make sure everythings fine and working
properly.
But now there's a problem.
If we log in as Jack, we can create the JacksDB databse, but we can also
create AS MANY databases as we want. This IS NOT how we set it up.
To my webhost this is a serious problem, because we want to charge money for
each database that you want setting up. But for some reason, all users that
we set up can create as many databases as they wish - even though the
mysql.user database says that NONE of our users have that privilege!
WHY is this happening?
This doesn't happen on Win98, but it does happen on our Win2000 server.
Anybody got any ideas?
Thanks,
- Jefferrs
* e-mail: jefferrs@blueyonder.co.uk