MySQL is currently open without authentication.
This results in all the database data made available publicly.
Severity: high
Fingerprint: cf350410ecceb5fd90095e7afbe90df93b31484c7351a7faf3429cf861f4fcb4
Databases: 32, row count: 136884, size: 7.8 MB Found table mysql.columns_priv with 0 records Found table mysql.db with 3 records Found table mysql.engine_cost with 2 records Found table mysql.event with 0 records Found table mysql.func with 0 records Found table mysql.general_log with 2 records Found table mysql.gtid_executed with 0 records Found table mysql.help_category with 50 records Found table mysql.help_keyword with 962 records Found table mysql.help_relation with 2460 records Found table mysql.help_topic with 851 records Found table mysql.innodb_index_stats with 10 records Found table mysql.innodb_table_stats with 3 records Found table mysql.ndb_binlog_index with 0 records Found table mysql.plugin with 0 records Found table mysql.proc with 48 records Found table mysql.procs_priv with 0 records Found table mysql.proxies_priv with 1 records Found table mysql.server_cost with 6 records Found table mysql.servers with 0 records Found table mysql.slave_master_info with 0 records Found table mysql.slave_relay_log_info with 0 records Found table mysql.slave_worker_info with 0 records Found table mysql.slow_log with 2 records Found table mysql.tables_priv with 2 records Found table mysql.time_zone with 1826 records Found table mysql.time_zone_leap_second with 0 records Found table mysql.time_zone_name with 1894 records Found table mysql.time_zone_transition with 119956 records Found table mysql.time_zone_transition_type with 8801 records Found table mysql.user with 5 records Found table nacos_devtest.test with 0 records
Open service 161.189.183.139:443
2024-06-20 10:08
HTTP/1.1 403 Forbidden Date: Thu, 20 Jun 2024 10:08:42 GMT Content-Type: application/json Content-Length: 136 Connection: close x-amzn-requestid: a76a7f11-536c-42f7-9ac9-6544cfd50d66 access-control-allow-origin: * {"Message":"User: anonymous is not authorized to perform: es:ESHttpGet because no resource-based policy allows the es:ESHttpGet action"}