Faulty MySQL permissions after a manual migration
Summary
Manuel Schmitt documents his exchange with another hosting provider after a manually created MySQL user unexpectedly gained access to other customers’ databases. The other provider traced the error to a user created manually after a server shutdown. According to its account, only this single user had wrong permissions.
Ideas
- Manual special migrations easily bypass the safeguards of standardised provisioning.
- An error can affect only one user and still allow access across tenants.
- Reporting openly to the operator allows quick correction without public identification.
- The four-eyes principle lowers the risk of security-critical individual changes.
Insights
- A claim to perfection is no substitute for controls in rare administrative special cases.
- Anonymised incident reports make structural risks visible without needlessly exposing those affected.
Facts
- Manuel published the incident anonymously and recommended additional checks.
Recommendations
- Check database permissions automatically against the expected tenant boundary.
- Have manual migrations with extended rights approved by a second person.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.