MySQL security and Windows

From: Date: Wed, 07 Nov 2001 14:24:13 +0000
Subject: MySQL security and Windows
Groups: php.windows 
Request: Send a blank email to php-windows+get-10257@lists.php.net to get a copy of this message
Hi, I've posted to this group before about this, but I'll give it a second shot: I represent a small webhost, running a normal M$ Windows2000 IIS5 server. Everything works fine. But, the users of our MySQL service can somehow create any number of databases that they like, *even though* we have set it up so users *can't* do that. For example, we'll create a imaginary user called 'Jack' and give him the rights to edit a database called 'JacksDB' using the following SQL command: GRANT ALL PRIVILEGES ON JacksDB.* TO Jack@localhost IDENTIFIED BY 'password'; After that's done, our user Jack has been created. But only with the rights to edit his own database (JacksDB). In fact, our friend Jack is listed in the mysql.user database as having no privileges ('N'). And under the mysql.db database, our user Jack is listed as having every privilege ('Y') on the database called JacksDB.* all except the Grant_priv. So this is all well and good, it's how it's supposed to be. We'll even do a FLUSH PRIVILEGES to make sure everythings fine and working properly. But now there's a problem. If we log in as Jack, we can create the JacksDB databse, but we can also create AS MANY databases as we want. This IS NOT how we set it up. To my webhost this is a serious problem, because we want to charge money for each database that you want setting up. But for some reason, all users that we set up can create as many databases as they wish - even though the mysql.user database says that NONE of our users have that privilege! WHY is this happening? This doesn't happen on Win98, but it does happen on our Win2000 server. Anybody got any ideas? Thanks, - Jefferrs * e-mail: jefferrs@blueyonder.co.uk

« previous php.windows (#10257) next »