1
0
mirror of https://github.com/MariaDB/server.git synced 2025-07-27 18:02:13 +03:00

MDEV-3915 COM_CHANGE_USER allows fast password brute-forcing

allow only three failed change_user per connection.
successful change_user do NOT reset the counter

tests/mysql_client_test.c:
  make --error to work for --change_user errors
This commit is contained in:
Sergei Golubchik
2013-01-25 00:17:39 +01:00
parent 8127e631de
commit bfc71e63a7
8 changed files with 164 additions and 79 deletions

View File

@ -1865,6 +1865,7 @@ public:
bool no_errors, password;
bool extra_port; /* If extra connection */
uint8 failed_com_change_user;
/**
Set to TRUE if execution of the current compound statement
can not continue. In particular, disables activation of