OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: acz [iSecureLabs] (aurelien.cabezoniSecureLabs.com)
Date: Tue Oct 02 2001 - 02:54:57 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hi all,

    WinMySQLadmin 1.1 store Mysql password in clear text in the file
    c:\winnt\my.ini

    ---<my.ini>---
    #This File was made using the WinMySQLadmin 1.1 Tool

    [mysqld]
    basedir=C:/mysql
    datadir=C:/mysql/data

    [WinMySQLadmin]
    Server=C:/mysql/bin/mysqld-nt.exe
    user=admin
    password=XXXXX (in clear text)
    QueryInterval=30
    ---<my.ini>---

    It can be dangerous if someone can remotly read any file on your NT box with
    typicall IIS hole such as
    http://packetstormsecurity.org/9905-exploits/ms.iis4.showcode.txt or
    anything else...

    ----
    Cabezon Aurélien
    http://www.iSecureLabs.com