bk99.de entertain the web since 1997

Faulty MySQL permissions after a manual migration

Summary

Manuel Schmitt documents his exchange with another hosting provider after a manually created MySQL user unexpectedly gained access to other customers’ databases. The other provider traced the error to a user created manually after a server shutdown. According to its account, only this single user had wrong permissions.

Ideas

  • Manual special migrations easily bypass the safeguards of standardised provisioning.
  • An error can affect only one user and still allow access across tenants.
  • Reporting openly to the operator allows quick correction without public identification.
  • The four-eyes principle lowers the risk of security-critical individual changes.

Insights

  • A claim to perfection is no substitute for controls in rare administrative special cases.
  • Anonymised incident reports make structural risks visible without needlessly exposing those affected.

Facts

  • Manuel published the incident anonymously and recommended additional checks.

Recommendations

  • Check database permissions automatically against the expected tenant boundary.
  • Have manual migrations with extended rights approved by a second person.

References

Read the original article on Hostblogger

Search the Web Archive