Results 1 to 2 of 2

Thread: Is it possible that zimbra mysql leaves the mysql root password empty?

Hybrid View

  1. #1
    Join Date
    Jul 2008
    Location
    Zurich
    Posts
    17
    Rep Power
    7

    Default Is it possible that zimbra mysql leaves the mysql root password empty?

    Hi,

    I was looking through our DB (we would like to monitor MySQL status) and I found:

    Code:
    mysql> select Host,User,Password from user ;
    +-----------------------------+--------+-----------------------------+
    | Host                        | User   | Password                    |
    +-----------------------------+--------+-----------------------------+
    | localhost                   | root   | *hash                       | 
    | zcs-be1.ewmail.everyware.ch | root   |                             | 
    | 127.0.0.1                   | root   |                             | 
    | localhost                   |        |                             | 
    | zcs-be1.ewmail.everyware.ch |        |                             | 
    | %                           | zimbra | *another*hash               | 
    | localhost                   | zimbra | *another*hash               | 
    | localhost.localdomain       | zimbra | *another*hash               | 
    | localhost.localdomain       | root   |                             | 
    +-----------------------------+--------+-----------------------------+
    9 rows in set (0.00 sec)
    Shouldn't a password for root be set universally?
    While a local user is needed to really exploit this, I still consider it to be "sub-optimal" ;-)



    Rainer

  2. #2
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,017
    Rep Power
    25

    Default

    Yes but it is root that is null ... If somebody gains access to your server as root that would be the least of my worries

Similar Threads

  1. Big Fubar on 5 FOSS GA Upgrade
    By uxbod in forum Administrators
    Replies: 24
    Last Post: 01-21-2008, 03:37 AM
  2. Major Issue - 5.0RC2 NE to 5.0GA NE failed
    By DougWare in forum Installation
    Replies: 7
    Last Post: 01-06-2008, 09:56 PM
  3. dspam logrotate errors
    By michaeln in forum Users
    Replies: 7
    Last Post: 02-19-2007, 12:45 PM
  4. 3.1 on FC4 problems
    By cohnhead in forum Installation
    Replies: 8
    Last Post: 05-26-2006, 12:16 PM
  5. FC3 Install and no zimbra ?
    By aws in forum Installation
    Replies: 10
    Last Post: 10-09-2005, 05:19 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •