Repository navigation
v1.5.1
What's new in 1.5.1
A security release. A review of the whole app found a number of ways a file, a web page or another program on the computer could get the app to do more than it should. All of them are fixed. Please update.
The local server
- Any program on the computer could use the app's server: the check of the token let a request with an empty list for a token through, and the token was in the page the server hands to anyone who asks. The token is now checked strictly, is no longer in the page (it comes in the address the app window opens with), and the server refuses requests from other web pages and anything but the app's own kind of request.
- Every response now tells the browser not to show the app inside another site and not to load anything from elsewhere.
- Settings could be made to run any program as a "client tool". A tool now has to be mysql or mysqldump, an .exe, on this computer, and Settings checks that when it saves as well.
Action needed for PAM / LDAP accounts. MySQL's client no longer sends a password as typed (PAM or LDAP) over SSL required on its own: that mode does not check the server's certificate, so someone in between could pose as the server and read it. Use verify-ca or verify, or - on a network you trust - tick the new PAM / LDAP sign-in box in the saved connection.
Import
- A dump file could run commands on your computer. MySQL's command-line client carries out
system <command>andtee <file>found in a file it loads; a dump someone sends you could hold them. Import now runs the client in binary mode, where it refuses every client command. Raw NUL bytes go through as well, so the "Binary mode" box is gone - it is always on. - A database or table name that starts with
-could be read by the client tools as an option. Names are now passed so that they are always names.
Read-only / safe mode
- Several statements that write got through:
EXPLAIN ANALYZEof a multi-table UPDATE or DELETE,SET GLOBALorPERSISTafter another assignment,SET RESOURCE GROUP,INTO OUTFILEafter an earlierINTO @var, a client command inside an optimizer hint (/*+ ... */), and names or strings with backslashes read the wrong way. All are refused now. - A connection saved as read-only stays read-only in the server, whatever the page asks - unless another saved connection to the same account is not read-only.
And
- Temporary files that hold a password are private to you, removed after use, and cleaned up at the next start if the app was killed. The SSH password goes to ssh through such a file, not its environment.
- The command-line tools refuse
LOAD DATA LOCAL, so a server cannot ask them for a file. - A password in SQL that the app logs, shows in a message or keeps with your open tabs is written as
'***'. - WAMP and XAMPP folders are no longer searched for client tools: any user of the computer can write to them. Pick their tools in Settings.
- Downloads: a changed MySQL download address has to be https, and the update notice opens only this project's release page.
- A saved transaction's Apply writes values for that session's own
sql_mode. - Table and column names with quotes, line breaks or names like
constructorno longer break Compare, the ERD, Export or Import.
The README has a new Security notes section on what read-only, import, SSL and SSH tunnels do and do not protect against.
Verify your download
This script is not code-signed. Compare what you downloaded against the SHA-256 below:
6ce969c408ffaa009e46402c60ce9001881e5b96a7cb7940f2504c48f9f306bc NOBSSQL.ps1
PowerShell: Get-FileHash .\NOBSSQL.ps1 -Algorithm SHA256
See CODE_SIGNING.md for what this does and does not prove.
Full Changelog: v1.5.0...v1.5.1