MySQL Rename Table? Explicit Data Directory? menu

User Tag List

Results 1 to 5 of 5
  1. #1
    Ebonesser's Avatar Member
    Reputation
    33
    Join Date
    Mar 2009
    Posts
    123
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    MySQL Rename Table? Explicit Data Directory?

    I searched my friends website with Acunetix and found this:
    The MySQL Enterprise Server is affected by multiple vulnerabilities.
    1. Using RENAME TABLE against a table with explicit DATA DIRECTORY and INDEX DIRECTORY options can be used to overwrite system table information.
    2. ALTER VIEW retained the original DEFINER value, even when altered by another user, which could allow that user to gain the access rights of the view.
    3. When using a FEDERATED table, the local server can be forced to crash if the remote server returns a result with fewer columns than expected.
    Somebody who knows how to execute or exploit at least nr 1 or 2?
    I can NOTHING about SQL or MySQL. Any help would be appreciated.
    I'm doing this for fun. To play a prank on my friend xD

    Ps: He's using
    MySQL Enterprise Server v.5.0.52

    MySQL Rename Table? Explicit Data Directory?
  2. #2
    chocochaos's Avatar Member
    Reputation
    55
    Join Date
    Jul 2008
    Posts
    29
    Thanks G/R
    0/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The only way to exploit those would be if you already have access to the database and can execute one of those queries, or if one of the scripts he uses has an sql injection vulnerabilty.
    So, your plan is probably not going to work...

  3. #3
    Danne206's Avatar Contributor
    Reputation
    183
    Join Date
    Jan 2008
    Posts
    717
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Google up SQL Injection.
    Dahnniel [DOT] s [AT] gmail [DOT] com

  4. #4
    Kiev's Avatar Contributor
    Reputation
    288
    Join Date
    Nov 2007
    Posts
    1,819
    Thanks G/R
    0/4
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    No one here will tell you (atleast publically) how to do this. As this site does not endorse hacking. xD




  5. #5
    Ebonesser's Avatar Member
    Reputation
    33
    Join Date
    Mar 2009
    Posts
    123
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    ok
    Thanks for th help then...

Similar Threads

  1. [Release] WildStar Data Table Editor
    By Jadd in forum WildStar Bots and Programs
    Replies: 20
    Last Post: 06-08-2014, 06:07 PM
  2. [MYSQL] tables missing?
    By Mizusan10 in forum WoW EMU Questions & Requests
    Replies: 5
    Last Post: 04-20-2010, 01:51 PM
  3. Possible mySQL table mix up
    By Denial is Ok in forum Suggestions
    Replies: 2
    Last Post: 08-31-2009, 09:39 PM
  4. Replies: 3
    Last Post: 06-06-2009, 07:08 PM
  5. ? Getting Data in and out of Tables Quickly
    By Tritan in forum World of Warcraft Emulator Servers
    Replies: 4
    Last Post: 06-10-2008, 11:26 AM
All times are GMT -5. The time now is 07:24 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search