[22763] in bugtraq

home help back first fref pref prev next nref lref last post

WinMySQLadmin 1.1 Store MySQL password in clear text

daemon@ATHENA.MIT.EDU (acz [iSecureLabs])
Tue Oct 2 11:23:24 2001

Message-ID: <05b801c14b17$8b319ce0$0501a8c0@London>
From: "acz [iSecureLabs]" <aurelien.cabezon@iSecureLabs.com>
To: "Vulnwatch@Vulnwatch. Org" <vulnwatch@vulnwatch.org>
Cc: "Bugtraq@Securityfocus.Com" <bugtraq@securityfocus.com>
Date: Tue, 2 Oct 2001 09:54:57 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

Hi all,

WinMySQLadmin 1.1 store Mysql password in clear text in the file
c:\winnt\my.ini

---<my.ini>---
#This File was made using the WinMySQLadmin 1.1 Tool

[mysqld]
basedir=C:/mysql
datadir=C:/mysql/data

[WinMySQLadmin]
Server=C:/mysql/bin/mysqld-nt.exe
user=admin
password=XXXXX (in clear text)
QueryInterval=30
---<my.ini>---

It can be dangerous if someone can remotly read any file on your NT box with
typicall IIS hole such as
http://packetstormsecurity.org/9905-exploits/ms.iis4.showcode.txt or
anything else...

----
Cabezon Aurélien
http://www.iSecureLabs.com



home help back first fref pref prev next nref lref last post