Mailing List Archive



Back to the month index Back to the list index

Axel Stegner (stegner@fb3-s7.math.tu-berlin.de)
Fri, 20 Sep 1996 14:20:04 +0200


Date: Fri, 20 Sep 1996 14:20:04 +0200
Message-Id: <199609201220.AA16525@fb3-s7.math.tu-berlin.de>
From: Axel Stegner <stegner@fb3-s7.math.tu-berlin.de>
Subject: [mSQL] msql access security problem

Hi !

I've been testing msql-1.0.16.
Is it right that the read/write username is not connected with the
hostname ?
I thing many users are believing that if they set msql.acl:
> #
> # Access control for mSQL
> #
>
> database=publications
> read=*
> write=root
> host=*
> access=local,remote

only the superuser can change the tables but any
root@hackerhost.anywhere.in.world
can create,change or drop them.

Is there a patch which allows to write:
write=write=root@localhost,write=root@localhost,admin@adminhost
?

I'm new to this list so I'm sorry if this subject has been dicussed yet.

Axel
--------------------------------------------------------------------------
To remove yourself from the Mini SQL mailing list send a message containing
"unsubscribe" to "unsubscribe" to msql-list-request@bunyip.com. Send a message containing
"info msql-list" to majordomo@bunyip.com for info on monthly archives of
the list. For more help, mail owner-msql-list@bunyip.com NOT the msql-list!