On GameSpot: Looking to buy a video game console?
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 6 of 11:
Next »
« Previous
I'll explain
There a ton of MySQL distrubutions for windows that bundle Apache/php/mysql all into one. they are for people who want to develop LAMP apps on their Windows boxes.

MySQL can easily be run under a less priveledged user account, but these LAMP for windows distributions just install everything so they run under the system account.

Combine this with the fact that developers, not system admins, install these LAMP packages on windows, and you end up with a bunch of MySQL deamons running as root, and open to the world.

NOw back to original quote you commented on:

"It really had nothing to with Windows itself, other than DBA's not properly configuring anything."

The problem is, these instances of MySQL were not installed by DBA's.

Oh yeah, and in general, Windows admins have a poorer understanding of network security than others.
Posted by: toadlife   Posted on: 01/29/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

whaaa?  JoeMama_z | 01/28/05
YES you can.... but  htotten | 01/28/05
thanks but,  JoeMama_z | 01/28/05
MySQL does run under a normal user account on Windows  Hugh Jass | 01/28/05
I'm confused.  Immanuel Tranz-Mischen | 01/29/05
I'll explain  toadlife | 01/29/05
and...  linuxoverwindows | 01/29/05
why other platforms weren't affected  toadlife | 01/29/05
Moral: use secure passwords, especially on the root account (nt)  CobraA1 | 01/30/05
Running at root?  DonPMitchell@... | 01/31/05
A couple of points, and maybe I missed something  Physco Dude | 01/31/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here