Go Back   HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials > ISPConfig 3 > General

Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
Reply
 
Thread Tools Display Modes
  #1  
Old 9th April 2009, 20:25
clark61 clark61 is offline
Junior Member
 
Join Date: Mar 2009
Location: Milano
Posts: 10
Thanks: 0
Thanked 0 Times in 0 Posts
Default mysql security question

Hi all,
a question about security
during the setup we comment bind_address 127.0.0.1 in /etc/mysql/my.cf.
Why we want that mysql listen on all addresess?
Isn't a risk for possibles attaks mysql injection?
Many thanks
Reply With Quote
Sponsored Links
  #2  
Old 10th April 2009, 11:12
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 37,001
Thanks: 840
Thanked 5,650 Times in 4,460 Posts
 
Default

Quote:
Why we want that mysql listen on all addresess?
It need sto listen on all addresses if you want to use a multiserver setup or if your clients shall be able to access it from outside. If you dont want tit to be accessible from outside you can also block it by enabling the firewall.

Quote:
Isn't a risk for possibles attaks mysql injection?
No. Mysql injection attacks are done trough vulnerabble scripts on your server as these scripts are already logged into the server. These scripts are connectiong to 127.0.0.1 anyway so this makes no difference.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Management/system config/settings & /server/settings not working!! dactor Installation/Configuration 9 6th February 2008 10:11
MYSQL; setting/updating the root password question... rh-penguin HOWTO-Related Questions 2 30th January 2007 19:47
Messed up ISPConfig-2.2.8 Upgrade Morons Installation/Configuration 4 29th November 2006 13:17
Quick question about Postfix + MySQL asterix HOWTO-Related Questions 5 12th September 2006 17:45
Mandriva 10.2 Perfect Setup Install Problems... ctroyp Installation/Configuration 12 30th December 2005 17:04


All times are GMT +2. The time now is 09:25.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.