|
- Readme First! - Read and follow the rules, otherwise your posts will be closed |
|
|
|
|
|
There are currently, 394 guest(s) and 0 member(s) that are online.
You are Anonymous user. You can register for free by clicking here |
|
|
|
|
|
|
MySQL has released information today about a new vulnerability. This exploit check has been integrated into a new Analyzer dot release: 1.89.1. Included in this dot release is the ability to display config.php values even if a MySQL connection isn't established.
View it here--> Analyzer 1.89.1
|
|
Posted on Friday, February 07 @ 22:26:07 CET by Zhen-Xjell |
|
|
|
|
| |
|
Average Score: 5 Votes: 1

|
|
|
|
|
|
|
| | The comments are owned by the poster. We aren't responsible for their content. |
| | | | |
| No Comments Allowed for Anonymous, please register | | | | |
Re: New MySQL Vulnerability (Score: 1) by ITEagle03 on Saturday, February 08 @ 15:40:00 CET (User Info | Send a Message) http://www.seanhiatt.ws | | Do you have a link referring to the MySQL vulnerability? I've searched around and haven't been able to find it. |
| | | | |
Re: New MySQL Vulnerability (Score: 1) by RStar23 on Saturday, February 08 @ 21:58:45 CET (User Info | Send a Message) | First, thanks for Analyzer - nice tool.
Second, I have done a full updated MySQL to 3.23.55 (was at 3.23.43). Now when I run Anaylzer 1.89.1 it still tells me that I have a vulnerable mysql client (3.23.39).
Since the update loaded my server and client code, I am not sure how this is happening. I would appreciate your insight.
thx
RStar23
|
Re: New MySQL Vulnerability (Score: 0) by Anonymous on Saturday, February 08 @ 22:13:18 CET | Join the club, I ran the analyzer, got the error about having a vunerable server (3.23.49) followed the link, downloaded the latest (3.23.55) shutdown my produciton server, disconnecting 179 customers, installed the update, rebooted the server and then re-ran the analyzer and it claims I have the wrong one still, (3.23.49). So, now, after pissing off almost 200 customers, I'm wondering if I was running the wrong one to start with.
Not a good thing here guys!!!!! |
]
Re: (Score: 1) by RStar23 on Monday, February 10 @ 21:08:01 CET (User Info | Send a Message) | I am assuming the analyzer is wrong in reporting that I have an old version client running. I have verified what I have installed and am comfortable that the right code is installed.
It is just a bit disarming to apply fixes and be told ya still have a problem ;>
|
]
| | | | |
Re: New MySQL Vulnerability (Score: 0) by Anonymous on Saturday, February 08 @ 22:13:34 CET | Join the club, I ran the analyzer, got the error about having a vunerable server (3.23.49) followed the link, downloaded the latest (3.23.55) shutdown my produciton server, disconnecting 179 customers, installed the update, rebooted the server and then re-ran the analyzer and it claims I have the wrong one still, (3.23.49). So, now, after pissing off almost 200 customers, I'm wondering if I was running the wrong one to start with.
Not a good thing here guys!!!!! |
Re: (Score: 1) by Zhen-Xjell on Saturday, February 08 @ 22:45:43 CET (User Info | Send a Message) http://castlecops.com | If you ran the upgrade per the mysql changelog then you are fine. I may have to tweak 1.89.1 for this. Thanks for the feedback.
And I'm sure you didn't piss off 200 customers. They should be happy they have a host who cares for their data security. |
]
| | | | |
Re: New MySQL Vulnerability (Score: 1) by Zhen-Xjell on Saturday, February 08 @ 22:38:56 CET (User Info | Send a Message) http://castlecops.com | | Per the mysql changelog if you upgraded you are fine. On running analyzer what version of the server and client does it say you have? |
]
Re: (Score: 1) by RStar23 on Monday, February 10 @ 21:04:20 CET (User Info | Send a Message) | post upgrade the analyzer does not find a problem with the server version, 3.23.55 but says I have a 3.23.39 client installed. What makes this even more puzzling is that bwefore the upgrade it said I had a 3.23.49 client.
RStar23 |
]
| | | | |
Re: New MySQL Vulnerability (Score: 0) by Anonymous on Sunday, February 09 @ 07:26:12 CET | Can you tell me why this 'tool' says i'm
running a old version of MySQL while i'm
running the latest release!
mysql --version
mysql Ver 12.17 Distrib 4.0.10-gamma, for pc-linux (i686)
mysqld --version
mysqld Ver 4.0.10-gamma for pc-linux on i686
Grtnx,
Jan Koetze |
| | | | | |