Thursday, August 2, 2012

MySQL anonymous user login

After a fresh install of mysql at our linux box server. I was able to login to mysql with any user which we didn't defined. 
[root@spica ~]# mysql -utest

Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 12
Server version: 5.1.61 Source distribution

Copyright (c) 2000, 2011, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> quit

To fix you need to delete the blank user at the mysql.user tables.
[root@spica ~]# mysql -uroot -p
Enter password:
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 14
Server version: 5.1.61 Source distribution

Copyright (c) 2000, 2011, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> show databases;
| Database           |
| information_schema |
| mysql              |
| test               |
3 rows in set (0.00 sec)

mysql> select user,host from mysql.user;
| user | host       |
| root |  |
|      | localhost  |
| root | localhost  |
|      | meitnerium |
| root | meitnerium |
5 rows in set (0.00 sec)

mysql> delete from mysql.user where user='';
Query OK, 2 rows affected (0.00 sec)

mysql> select user,host from mysql.user;
| user | host       |
| root |  |
| root | localhost  |
| root | meitnerium |
3 rows in set (0.00 sec)

mysql> flush privileges;
Query OK, 0 rows affected (0.00 sec)

mysql> quit
[root@spica ~]# mysql -utest
ERROR 1045 (28000): Access denied for user 'test'@'localhost' (using password: NO)
[root@spica ~]#

