Home Forum User CP Browse Members Calendar Register Today!  
Get New posts Faq / Help?
   


Not A Member Yet? Register today and become part of the community.

Go Back   Webmaster Forum - 9MB.com > Webmaster Forum > General Webmaster Discussion

General Webmaster Discussion Discuss anything webmaster related.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-27-2008, 07:43 AM
pesklas12
Status: Offline
Junior Member
 
Join Date: Feb 2008
Posts: 12
iTrader: (0)
Rep Power: 0
pesklas12 is an unknown quantity at this point
Cool How to secure mysql database

Please correct me if i'm wrong. I came accross that mysql databases not really secure.

I just new in the company. My company have multiple servers using linux OS with mysql databases located at many branches and for some reasons I believed that mysql databases are accessible without permission by some people in the branches.

For your information, the branches and its staffs not belong to our company. They are just running our systems. They have no right to access our servers although the servers located at their places.

I am so confident that they use some brute force or any related software to get mysql username and password

Any ideas.....

Last edited by pesklas12; 02-27-2008 at 08:08 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-27-2008, 07:54 AM
Doskono's Avatar
Doskono
Status: Offline
Senior Member
 
Join Date: Jul 2007
Location: Hong-Kong S.A.R.
Posts: 880
iTrader: (1)
Rep Power: 17
Doskono is on a distinguished road
Send a message via Skype™ to Doskono
Well at this point it's hard to say what is secure and what isn't. If you ask me, nothing is secure! There are always ways of manipulating things which is not yours. Some things are harder than others but the answer remains.

I woudn't be worried of any brute force attacks as any brute force attacks would require multiple months before finding the username and the password combination. You may want to change your password to not a dictionary word and a combination of both letters and numbers. The lazy way of doing a brute force attack is known as a dictionary attack, this would take words of the dictionary and enter them until it matches to the password, if you're password is not a one word password then you should be fine from brute force attacks.

I will tell you this, MYSQL is the largest opensource database software in my opinion and by far the best and user friendly. The reason forums like vB, phpbb3 use mysql amongst others is because it is secure enough for any business or website out there.

also to for security reasons you should always encrypt passwords before inserting it into the database.

So your answer is yes, mysql is secure. I woudn't worry about it too much.
__________________
Common sense ain't common.
Open Source Script Junkie
I seriously need to get better welcome messages...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-27-2008, 08:15 AM
pesklas12
Status: Offline
Junior Member
 
Join Date: Feb 2008
Posts: 12
iTrader: (0)
Rep Power: 0
pesklas12 is an unknown quantity at this point
Dokono, thanks for the long explanation. At least i get some ideas what are the next steps.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -4. The time now is 06:55 AM.

Skin Design By vBSkinworks



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC8
Copyright (c) 2007-2008 - All Rights Reserved - 9MB.com