[imp] mysql port 3306

Anil Madhavapeddy anil@recoil.org
Tue, 21 Nov 2000 16:28:08 -0000


Mark Orenstein wrote:
> 
> I'm running sendmail/imap/horde/imp/mysql on one PC.  I'm looking to secure
> this PC as much as I can.  Via a netstat -anp, I've noticed that mysql is
> listening on port 3306.  Is it possible to use ipchains to only allow
> localhost source address access to this port?
> 

Just bind the MySQL process to listen only on the 127.0.0.1 (localhost)
address, so it won't be seen from the outside world.  Or a domain socket
only (I believe it has some special behaviour for localhost anyhows).

You shouldn't really need to mess with ipchains (I assume you are
running Linux).

--
 Anil Madhavapeddy / "Oi luv moi brick!" 
 anil@recoil.org   /       - Father Jack