Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 22 Jan 2008 16:08:20 +0100
From:      Jordi Espasa Clofent <jordi.espasa@opengea.org>
To:        freebsd-security@freebsd.org
Subject:   Re: denyhosts-like app for MySQLd?
Message-ID:  <479606E4.2070607@opengea.org>
In-Reply-To: <47953894.8020906@netoyen.net>
References:  <47946AD3.2020601@opengea.org> <47953894.8020906@netoyen.net>

next in thread | previous in thread | raw e-mail | index | archive | help
> why do you open your mysql port to the world?
> 
> if you want to let users in from any place, then an ssh tunnel is safer 
> (yes, works even on windows, using putty or whatever. and a user who 
> finds this difficult shouldn't be able to run sql commands!).

I completely agree with you; the problem is always the same: the 
decisions are taken by non-technical staff in a lot of times.
I've proposed a ssh tunnels for MySQL remote connections... but it means 
"so hard" for final customers....

> If this is too much, at least use a different port to reduce the noise 
> (This won't add security, but will somehow limit exposure).scribe@freebsd.org"

Of course.

-- 
Thanks,
Jordi Espasa Clofent



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?479606E4.2070607>