1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

What can someone do if they have my website's database user password?

Discussion in 'Security' started by OSForums.net, Jun 19, 2015.

  1. #1
    My website is on Wordpress. Say someone knows my username and password for my database. Without knowing my cPanel password or wordpress admin password, what can they possibly do with only the database username and password?

    And how would they do it? Like where would they log in to my database from?
     
    OSForums.net, Jun 19, 2015 IP
  2. Karen May Jones

    Karen May Jones Prominent Member

    Messages:
    3,469
    Likes Received:
    290
    Best Answers:
    1
    Trophy Points:
    380
    #2
    Did somebody get ahold of your wp config file?
     
    Karen May Jones, Jun 19, 2015 IP
  3. OSForums.net

    OSForums.net Greenhorn

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    11
    #3
    No, I'm just asking what they can do and how they can do it.
     
    OSForums.net, Jun 19, 2015 IP
  4. Karen May Jones

    Karen May Jones Prominent Member

    Messages:
    3,469
    Likes Received:
    290
    Best Answers:
    1
    Trophy Points:
    380
    #4
    Yeah, I dont think anyone is going to guide you through that. It could be a bad idea.
     
    Karen May Jones, Jun 20, 2015 IP
  5. kulasingha

    kulasingha Active Member

    Messages:
    27
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    58
    Digital Goods:
    1
    #5
    If they can login to your WP dashboard they can easily delete your posted content,images,videos,theme,plugins and even add malware codes to your content post or to get revenue from publising their advertising codes, so basically they are the new owner of your WP website.

    What I suggest you is that you do not want to know how they do it, you only want to get more protective messures to your WP website, like adding some free WP protection tools like, Wordfence free plugin, All In One WP Security, Sucuri security, i themes security.
    These can harden your login page and many other protection methods to your wp website.

    Thank you take care.
     
    kulasingha, Jun 20, 2015 IP
  6. PoPSiCLe

    PoPSiCLe Illustrious Member

    Messages:
    4,623
    Likes Received:
    725
    Best Answers:
    152
    Trophy Points:
    470
    #6
    Depends what is allowed on the host. If I had you login-information to the mysql-server, I could fire up a local mysql-suite, like HeidiSQL, input your information, and have full access to your database. From there, I could alter, insert, delete and do all kinds of bad stuff. This requires that the host allows remote logins to the database (most hosts allow this). No need for any access to cPanel or similar. Also, take note that they could replace the passwords for user-accounts, thereby gaining access to the admin-panel of wordpress (not that they'd need to, they already have access to the database), change theme-files etc. If the database contain other stuff than just the wordpress install, they would also have access to that.
     
    PoPSiCLe, Jun 20, 2015 IP
  7. Matthew Sayle

    Matthew Sayle Prominent Member

    Messages:
    3,325
    Likes Received:
    464
    Best Answers:
    1
    Trophy Points:
    385
    #7
    If you're worried about something, simply change your DB password :)
     
    Matthew Sayle, Jun 20, 2015 IP
  8. BMR777

    BMR777 Well-Known Member

    Messages:
    145
    Likes Received:
    8
    Best Answers:
    1
    Trophy Points:
    140
    #8
    Most hosts have remote connection disabled by default, however even if remote connection is disabled the bad user could still gain access potentially by creating a hosting account on the same server as your website, such as by registering an account with the web host, then use a PHP script to connect to your database from the server using your DB information. It takes a bit more work on the attacker's part, but it's doable.
     
    BMR777, Jul 10, 2015 IP
  9. PoPSiCLe

    PoPSiCLe Illustrious Member

    Messages:
    4,623
    Likes Received:
    725
    Best Answers:
    152
    Trophy Points:
    470
    #9
    I think you're overly confident in the knowledge and capabilities of most hosts... my experience is that many hosts have some form of remote access - logged, perhaps, but usually it's possible - some hosts even uses the same password, or similar passwords for accessing different parts of the server (say both FTP / SFTP and MySQL) and so forth and so on... basically, if any login-info gets out, change it - immediately!
     
    PoPSiCLe, Jul 11, 2015 IP