Skip to content

Comment on Root access to MySQL.com sold for $3k - now serving malwareparent

Comments

Don't even the most basic MySQL install tutorials have you create a separate user and group for the database user?

If you're running MySQL as root, you're trying hard to get owned.

Pretty sure he meant "rooted" in the sense of "inserted exploits into the codebase". In some sense that's much worse that mere root access to the host. Such a database could, for example, phone home with all updates to tables named "passwords", etc...

And even in the more banal sense you interpreted, sure: you might not run mysql.com-sourced daemons as root. But you almost certainly run the mysql command line utility as root from time to time.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.