Hi Zachery
Things like DROP, ALTER and CREATE bother me - perhaps unnecessarily, as I seem to be the only one! GRANT seems dodgy too (and since you said before it wasn't used, I will remove it).
But it does seem to me that in normal use (ie - a logged in user making and reading posts) the vBulletin app needs to do CRUD, but not much else. Doing updates and maintenance tasks clearly need more - but I would have expected a separate user with increased perms used for only those processes that need it.
I can't help wondering if this is an issue, as previous colleagues who know more than I have insisted on using accounts with the minimal perms for the tasks in hand, and have claimed this is more secure.
And, not being funny, but vB seems quite prone to security breeches... which is another reason why this seems suspiciously lax to me.
But as I said - I know very little about security and how that sort of stuff works - so am happy to accept I am probably wrong.
cheerio, Mike
|