Home Database Mysql Tutorial Mysql security precautions

Mysql security precautions

Dec 16, 2016 am 11:25 AM

When using MySQL, security issues cannot be ignored. The following are 23 notes from MySQL:

 1. If the connection between the client and the server needs to span and pass through an untrusted network, then you need to use an SSH tunnel to encrypt the communication of the connection.

  2. Use the set passWord statement to change the user's password. Three steps. First log in to the database system with "mysql -u root", then "mysql> update mysql.user set password=password('newpwd')", and finally execute Just “flush PRivileges”.

  3. Attacks that need to be guarded against include anti-eavesdropping, tampering, replay, denial of service, etc., which do not involve availability and fault tolerance. All connections, queries, and other operations are completed using security measures based on ACL (access control list). There is also some support for SSL connections.

 4. Any other user except the root user is not allowed to access the user table in the mysql main database;

 Once the encrypted user password stored in the user table is leaked, others can use the user name at will/ Database corresponding to the password; 5. Use grant and revoke statements to perform user access control work; 6. Do not use plain text passwords, but use one-way hash functions such as md5() and sha1() to set them Password;

 7. Do not use words in the dictionary as passwords;

 8. Use firewalls to remove 50% of external risks, and let the database system work behind the firewall, or place it in the DMZ zone;

 9. Use nmap to scan port 3306 from the Internet, or use telnet server_host 3306 to test. Access to TCP port 3306 of the database server from an untrusted network is not allowed, so settings need to be made on the firewall or router;

 10. In order to prevent illegal parameters from being maliciously passed in, such as where ID=234, but others enter where ID=234 OR 1=1, causing all to be displayed, so use '' or "" to use strings in the web form, and use strings in the dynamic URL Adding %22 represents double quotes, %23 represents pound sign, and %27 represents single quotes; it is very dangerous to pass unchecked values ​​to the mysql database;

 11. Check the size when passing data to mysql;

12. Applications that need to connect to the database should use a general user account, and only open a few necessary permissions to the user; 13. Use specific 'escape character' functions in various programming interfaces (C C++ php Perl java JDBC, etc.) ;

  When using mysql database on the Internet, be sure not to transmit plain text data, and use SSL and SSH encryption to transmit data;

  14. Learn to use tcpdump and strings tools to check the security of transmitted data, such as tcpdump -l -i eth0 -w -src or dst port 3306   strings. Start the mysql database service as an ordinary user;

 15. Do not use the link symbol of the table, select the parameter --skip-symbolic-links; 16. Make sure that only the user who starts the database service in the mysql directory can access the database service. The file has read and write permissions;

 17. Process or super permissions are not allowed to be given to non-administrative users. The mysqladmin processlist can list the currently executed query text; super permissions can be used to cut off client connections and change the status of server operating parameters. , control the server that copies and replicates the database;

  18. File permissions are not given to users other than administrators to prevent the problem of loading data '/etc/passwd' into the table and then using select to display it;

  19. If not If you believe in the service of the DNS service company, you can only set the IP numeric address in the host name permission table;

 20. Use the max_user_connections variable to make the mysqld service process limit the number of connections for a specified account;

 21. The grant statement also supports resources Control options;

 22. Start the security option switch of the mysqld service process, --local-infile=0 or 1. If it is 0, the client program cannot use local load data. An example of grant grant insert(user) on mysql.user to 'user_name'@'host_name'; If you use --skip-grant-tables, the system will not perform any access control on any user's access, but you can use mysqladmin flush-privileges or mysqladmin reload to enable access control; default The situation is that the show databases statement is open to all users and can be turned off with --skip-show-databases.

 23. When encountering Error 1045 (28000) access Denied for user 'root'@'localhost' (Using password:NO), you need to reset the password. The specific method is: first use --skip-grant-tables Start mysqld with the parameters, then execute mysql -u root mysql,mysql>update user set password=password('newpassword') where user='root';mysql>Flush privileges;, and finally restart mysql.

The above is the content of Mysql security precautions. For more related articles, please pay attention to the PHP Chinese website (www.php.cn)!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Nordhold: Fusion System, Explained
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1670
14
PHP Tutorial
1274
29
C# Tutorial
1256
24
Laravel Introduction Example Laravel Introduction Example Apr 18, 2025 pm 12:45 PM

Laravel is a PHP framework for easy building of web applications. It provides a range of powerful features including: Installation: Install the Laravel CLI globally with Composer and create applications in the project directory. Routing: Define the relationship between the URL and the handler in routes/web.php. View: Create a view in resources/views to render the application's interface. Database Integration: Provides out-of-the-box integration with databases such as MySQL and uses migration to create and modify tables. Model and Controller: The model represents the database entity and the controller processes HTTP requests.

MySQL and phpMyAdmin: Core Features and Functions MySQL and phpMyAdmin: Core Features and Functions Apr 22, 2025 am 12:12 AM

MySQL and phpMyAdmin are powerful database management tools. 1) MySQL is used to create databases and tables, and to execute DML and SQL queries. 2) phpMyAdmin provides an intuitive interface for database management, table structure management, data operations and user permission management.

MySQL vs. Other Programming Languages: A Comparison MySQL vs. Other Programming Languages: A Comparison Apr 19, 2025 am 12:22 AM

Compared with other programming languages, MySQL is mainly used to store and manage data, while other languages ​​such as Python, Java, and C are used for logical processing and application development. MySQL is known for its high performance, scalability and cross-platform support, suitable for data management needs, while other languages ​​have advantages in their respective fields such as data analytics, enterprise applications, and system programming.

Laravel framework installation method Laravel framework installation method Apr 18, 2025 pm 12:54 PM

Article summary: This article provides detailed step-by-step instructions to guide readers on how to easily install the Laravel framework. Laravel is a powerful PHP framework that speeds up the development process of web applications. This tutorial covers the installation process from system requirements to configuring databases and setting up routing. By following these steps, readers can quickly and efficiently lay a solid foundation for their Laravel project.

Explain the purpose of foreign keys in MySQL. Explain the purpose of foreign keys in MySQL. Apr 25, 2025 am 12:17 AM

In MySQL, the function of foreign keys is to establish the relationship between tables and ensure the consistency and integrity of the data. Foreign keys maintain the effectiveness of data through reference integrity checks and cascading operations. Pay attention to performance optimization and avoid common errors when using them.

Compare and contrast MySQL and MariaDB. Compare and contrast MySQL and MariaDB. Apr 26, 2025 am 12:08 AM

The main difference between MySQL and MariaDB is performance, functionality and license: 1. MySQL is developed by Oracle, and MariaDB is its fork. 2. MariaDB may perform better in high load environments. 3.MariaDB provides more storage engines and functions. 4.MySQL adopts a dual license, and MariaDB is completely open source. The existing infrastructure, performance requirements, functional requirements and license costs should be taken into account when choosing.

What software is better for yi framework? Recommended software for yi framework What software is better for yi framework? Recommended software for yi framework Apr 18, 2025 pm 11:03 PM

Abstract of the first paragraph of the article: When choosing software to develop Yi framework applications, multiple factors need to be considered. While native mobile application development tools such as XCode and Android Studio can provide strong control and flexibility, cross-platform frameworks such as React Native and Flutter are becoming increasingly popular with the benefits of being able to deploy to multiple platforms at once. For developers new to mobile development, low-code or no-code platforms such as AppSheet and Glide can quickly and easily build applications. Additionally, cloud service providers such as AWS Amplify and Firebase provide comprehensive tools

SQL vs. MySQL: Clarifying the Relationship Between the Two SQL vs. MySQL: Clarifying the Relationship Between the Two Apr 24, 2025 am 12:02 AM

SQL is a standard language for managing relational databases, while MySQL is a database management system that uses SQL. SQL defines ways to interact with a database, including CRUD operations, while MySQL implements the SQL standard and provides additional features such as stored procedures and triggers.

See all articles