<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Micheal Savoie &#187; Database User</title>
	<atom:link href="http://michealsavoie.com/welcome/tag/database-user/feed/" rel="self" type="application/rss+xml" />
	<link>http://michealsavoie.com/welcome</link>
	<description>Helping People Help Themselves!</description>
	<lastBuildDate>Tue, 22 May 2012 19:15:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<copyright>2006-2007 </copyright>
	<managingEditor>admin@traf-x.com (Micheal Savoie)</managingEditor>
	<webMaster>admin@traf-x.com (Micheal Savoie)</webMaster>
	<image>
		<url>http://michealsavoie.com/welcome/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Micheal Savoie</title>
		<link>http://michealsavoie.com/welcome</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Find out what Micheal Savoie is up to.</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>Micheal Savoie</itunes:author>
	<itunes:owner>
		<itunes:name>Micheal Savoie</itunes:name>
		<itunes:email>admin@traf-x.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://michealsavoie.com/welcome/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Fixing The Fantastico Security Flaw</title>
		<link>http://michealsavoie.com/welcome/187/fixing-the-fantastico-security-flaw/</link>
		<comments>http://michealsavoie.com/welcome/187/fixing-the-fantastico-security-flaw/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 18:40:35 +0000</pubDate>
		<dc:creator>Micheal Savoie</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Blog Tips]]></category>
		<category><![CDATA[Community]]></category>
		<category><![CDATA[assigning a user to a MySQL database in cpanel]]></category>
		<category><![CDATA[Binder]]></category>
		<category><![CDATA[Content Management Systems]]></category>
		<category><![CDATA[Copy And Paste]]></category>
		<category><![CDATA[create a new MySQL database user]]></category>
		<category><![CDATA[create new MySQL database]]></category>
		<category><![CDATA[Database Name]]></category>
		<category><![CDATA[database replacement]]></category>
		<category><![CDATA[Database User]]></category>
		<category><![CDATA[exporting a MySQL database]]></category>
		<category><![CDATA[Fantastico]]></category>
		<category><![CDATA[fix fantastico security flaw]]></category>
		<category><![CDATA[Hacker Password]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Importing A MySQL Databse]]></category>
		<category><![CDATA[Mysql Databases]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[new user]]></category>
		<category><![CDATA[Notepad Document]]></category>
		<category><![CDATA[Password Hack]]></category>
		<category><![CDATA[Password Hacker]]></category>
		<category><![CDATA[Pdf File]]></category>
		<category><![CDATA[Scratch]]></category>
		<category><![CDATA[Scripts]]></category>
		<category><![CDATA[Security Flaw]]></category>
		<category><![CDATA[Snap]]></category>
		<category><![CDATA[Spam Control]]></category>
		<category><![CDATA[Video Tutorials]]></category>
		<category><![CDATA[Webmaster World]]></category>

		<guid isPermaLink="false">http://michealsavoie.com/welcome/index.php/2008/11/21/fixing-the-fantastico-security-flaw/</guid>
		<description><![CDATA[Editor&#8217;s Note: Since this post was published, I turned it into a PDF file so you can print it out to keep in your binder so you can reach for it whenever you have a Fantastico Blog to fix. http://myblogginschool.com/fantastico-fix/ We also have a service where for $47 we will fix the security flaw in [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><strong>Editor&#8217;s Note:</strong><br />
Since this post was published, I turned it into a PDF file so you can print it out to keep in your binder so you can reach for it whenever you have a Fantastico Blog to fix.<br />
<a href="http://myblogginschool.com/fantastico-fix/" target="_blank">http://myblogginschool.com/fantastico-fix/</a></p>
<p>We also have a service where for $47 we will fix the security flaw in your blog for you, upgrade it to the newest version (currently 2.7), update your plugins (install necessary ones for SEO, security and Spam control) and back up your database.<br />
<a href="http://mybloggingschool.com/hired-fix/">http://mybloggingschool.com/hired-fix/</a></p>
</blockquote>
<p>Fantastico is the coolest thing to come to the webmaster world since cpanel!&nbsp; It makes it a snap to install blogs, content management systems and many other scripts that a webmaster needs to make an interactive blog.</p>
<p><b>Problem is, the Fantastico script has a fatal flaw&#8230;</b></p>
<p>When Fantastico creates your WordPress installation (and any installation it ever performs), it uses the same database name and database username&#8230; Hackers only need to figure out your database password to hack into your site if they figure out you are using fantastico.</p>
<p><b>So what do you do?</b></p>
<p>I recommend always installing your blog from scratch&#8230; install using the wordpress download and upload it to your website, then perform the installation manually.&nbsp; I teach this in my blog installer certification course at <a target="_blank" href="http://MyBloggingSchool.com">MyBloggingSchool.com</a> using video tutorials, to make sure you are following along step by step.</p>
<p>But if you have already used Fantastico and you have a blog you don&#8217;t want to delete&#8230; </p>
<p><b>Here Is How To Secure It!</b></p>
<ol>
<li>Log into your cpanel. Then select the MySQL Databases icon.</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/database-editor.jpg" title="Fixing The Fantastico Security Flaw" alt="database editor Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Scroll down until you get to the add a database user section.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/create-db-user.jpg" title="Fixing The Fantastico Security Flaw" alt="create db user Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Use the Generate Password button to create a very hacker safe password and once you have chosen to use that password, copy and paste the password it gives you into a notepad document.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/generate-db-password.jpg" title="Fixing The Fantastico Security Flaw" alt="generate db password Fixing The Fantastico Security Flaw" /></p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/db-password.jpg" title="Fixing The Fantastico Security Flaw" alt="db password Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Then Click on Create User Button to finish creating the user.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/create-user.jpg" title="Fixing The Fantastico Security Flaw" alt="create user Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Make a note of the username and password, to make sure you have it saved in your notepad.&nbsp; You will see a message like this:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/user-created.jpg" title="Fixing The Fantastico Security Flaw" alt="user created Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Now we need to create a BRAND NEW database&#8230; (You can actually skip this section and go to step #8 if you feel squeamish about exporting and importing your database.&nbsp; You are making your installation more secure by changing 2 of the 3 items hackers need to compromise your WordPress installation, but I highly recommend going all the way through and really securing your installation&#8230;)
</li>
<li>Click Go Back to get back to the database management area. Give your new database a hard to figure out name (don&#8217;t use this one&#8230;):
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/create-new-db.jpg" title="Fixing The Fantastico Security Flaw" alt="create new db Fixing The Fantastico Security Flaw" /></p>
<p>Click on Create Database after you have entered a name.</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/db-created.jpg" title="Fixing The Fantastico Security Flaw" alt="db created Fixing The Fantastico Security Flaw" /></p>
<p>Click Go Back.</p>
</li>
<li>As you can see, you now have a database with no user attached.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/need-user-for-db.jpg" title="Fixing The Fantastico Security Flaw" alt="need user for db Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Let&#8217;s add a user to our WordPress Database by scrolling down to the Add User To Database section:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/add-user-to-db.jpg" title="Fixing The Fantastico Security Flaw" alt="add user to db Fixing The Fantastico Security Flaw" /></p>
<p>Select the database name and username that you created. (If you skipped steps 7 &amp; 8, you will use wrdp1 as the database name). Then you click Add.</p>
</li>
<li>Select the checkbox next to ALL PRIVILEGES before clicking on the Make Changes button.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/give-privileges-to-user.jpg" title="Fixing The Fantastico Security Flaw" alt="give privileges to user Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Once you have added the user to the database copy the success message to your notepad:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/copy-db-info-to-notepad.jpg" title="Fixing The Fantastico Security Flaw" alt="copy db info to notepad Fixing The Fantastico Security Flaw" /></p>
<p>This will make it much easier to edit your configuration file when we get to that step.</p>
</li>
<li>Here is what you should see in your notepad:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/saved-to-notepad.jpg" title="Fixing The Fantastico Security Flaw" alt="saved to notepad Fixing The Fantastico Security Flaw" /></p>
</li>
<li>And when you look at the database table, you will see your database now has a user attached:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/user-and-db-together.jpg" title="Fixing The Fantastico Security Flaw" alt="user and db together Fixing The Fantastico Security Flaw" /></p>
</li>
<li>If you are not changing the database ignore steps 15 through 21&#8230;
</li>
<li>Next click on the home button on the top of the page and then select&nbsp; phpMyAdmin from the Databases Section of cpanel.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/select-phpmyadmin.jpg" title="Fixing The Fantastico Security Flaw" alt="select phpmyadmin Fixing The Fantastico Security Flaw" /></p>
</li>
<li>First you will make a SQL backup of your old database.&nbsp; Select wrdp1 from the drop down menu on the left:
<p><img style="max-width: 800px; float: none;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/choose-old-db.jpg" title="Fixing The Fantastico Security Flaw" alt="choose old db Fixing The Fantastico Security Flaw" /></p>
<p>We are going to Export the database in SQL format and save it to your hard drive so that we can then create an exact copy of your database from the&nbsp; exported file.</p>
</li>
<li>On the right section of the screen, select Export.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/select-export.jpg" title="Fixing The Fantastico Security Flaw" alt="select export Fixing The Fantastico Security Flaw" /></p>
</li>
<li>The next screen will have many checkboxes already checked, but you want to ensure that you check Add CREATE PROCEDURE / FUNCTION because we want to create these tables in the new database.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/export-sql.jpg" title="Fixing The Fantastico Security Flaw" alt="export sql Fixing The Fantastico Security Flaw" /></p>
<p>In the picture, the checkbox directly above the RED LINE is the one you should check.&nbsp; It is not usually checked by default.</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/sql-save-file.jpg" title="Fixing The Fantastico Security Flaw" alt="sql save file Fixing The Fantastico Security Flaw" /></p>
<p>You can leave the file name template as is, and click Go.&nbsp; You will be prompted to Open or Save the file&#8230; choose save.&nbsp; Make a note as to where you are saving it.</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/sql-save-to-disk.jpg" title="Fixing The Fantastico Security Flaw" alt="sql save to disk Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Now use the drop down menu on the left and choose your new database name.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/choose-new-db.jpg" title="Fixing The Fantastico Security Flaw" alt="choose new db Fixing The Fantastico Security Flaw" /></p>
<p>You should have no tables in this database&#8230; but we are going to change that&#8230;</p>
</li>
<li>On the right choose Import:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/select-import.jpg" title="Fixing The Fantastico Security Flaw" alt="select import Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Click on Browse to locate the SQL file you just saved to your hard drive.
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/phpmyadmin-import-sql.jpg" title="Fixing The Fantastico Security Flaw" alt="phpmyadmin import sql Fixing The Fantastico Security Flaw" /></p>
<p>Click Go once you have found and selected your database SQL file.&nbsp; It may take a few minutes for it to upload and process, but you will know you have succeeded when you see your database on the left side of the screen with the same tables as the old database.</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/database-import-success.jpg" title="Fixing The Fantastico Security Flaw" alt="database import success Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Now we are ready to change our configuration file&#8230; go back to the cpanel screen (it is probably in another tab on your browser).&nbsp; Choose File Manager:
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/select-file-manager.jpg" title="Fixing The Fantastico Security Flaw" alt="select file manager Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Once File Manager has opened, select the root directory of your blog (you will be able to tell because it will have three folders in it (wp-admin, wp-content and wp-includes in it).&nbsp; You want to select the file wp-config.php and use the Code Editor (or file editor on older versions of cpanel).
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/wp-config-file-manager.jpg" title="Fixing The Fantastico Security Flaw" alt="wp config file manager Fixing The Fantastico Security Flaw" /></p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/code-editor.jpg" title="Fixing The Fantastico Security Flaw" alt="code editor Fixing The Fantastico Security Flaw" /></p>
</li>
<li>This is what your code editor screen will look like (file editor will not have the line numbers, but will work the same way):
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/wp-config-edit.jpg" title="Fixing The Fantastico Security Flaw" alt="wp config edit Fixing The Fantastico Security Flaw" /></p>
<p>Replace the items between the quotes so that you replace the old wrdp1 database and username are the new ones and replace the old password with your new one.&nbsp; Like this:</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/new-user-db-password.jpg" title="Fixing The Fantastico Security Flaw" alt="new user db password Fixing The Fantastico Security Flaw" /></p>
<p>Then click Save Changes:</p>
<p><img style="max-width: 800px;" src="http://michealsavoie.com/welcome/wp-content/uploads/2008/11/save-changes.jpg" title="Fixing The Fantastico Security Flaw" alt="save changes Fixing The Fantastico Security Flaw" /></p>
</li>
<li>Go to your blog and make sure that everything is working the way it was before&#8230;
</li>
<li>At this point you only have to go back to cpanel, and go to the database page and delete the old user and old database from your system.&nbsp; I would wait a couple of days to make sure that you have no problems with the blog installation before deleting them in case you want to revert back to the old one&#8230;</li>
</ol>
<p>Here is the blog that I did the change on for this exercise: <a target="_blank" href="http://yourdirectorywebsite.info/blog">http://yourdirectorywebsite.info/blog</a> <br />As you can see that it is still going the way it was before&#8230;</p>
<p>I hope this was helpful for you. If it was, please leave a comment or link to this article from your blog.</p>
<p><b>Limited Engagement&#8230;</b></p>
<p>This may be gone before you finish reading this post&#8230;</p>
<p>Alex Jeffreys has opened up a coaching program for a very limited time, in fact, it is very possible that he has already closed it because each time someone talks about, another 10 to 15 people sign up!</p>
<p>I spent some time watching the 37 minute video at this link:</p>
<p><a target="_blank" href="http://nexurl.com/WTF">http://nexurl.com/WTF</a></p>
<p>Here is a guy who makes over $20k per month promising to coach you to $6k per month!&nbsp; How can he promise that?&nbsp; He has learned from the best, he was a student of Mike Filsaime and Rich Schefren (Mike Filsaime&#8217;s mentor) so you know that the basics are covered&#8230;</p>
<p>Alex has had a wild couple years and he is headed to 7 figures in 2009, and he want to bring people along as his mentees!&nbsp; I couldn&#8217;t think of someone more exciting to learn the basics to the advanced from.&nbsp; If you want to do this, you have to watch the video, so make sure you have 37 minutes&#8230; he doesn&#8217;t give you an early way to the signup page, because he wants to make sure you are committed to it. (If you can&#8217;t sit through 37 minutes, how are you going to do what it takes to make $6k per month?)</p>
<p><a target="_blank" href="http://nexurl.com/WTF">http://nexurl.com/WTF</a></p>
<p>Have an amazing day!</p>
<p>Micheal Savoie<br /><a target="_blank" href="http://twitter.com/michealsavoie">http://twitter.com/michealsavoie</a></p>
<p>PS &#8211; If you like the information I am giving about blogs, I suggest you check out <a target="_blank" href="http://MyBloggingSchool.com">MyBloggingSchool.com</a> where I teach setting up blogs from the ground up!&nbsp; The goal for <a target="_blank" href="http://MyBloggingSchool.com">MyBloggingSchool.com</a> is to train and certify 50 blog installers for a project I am launching in June.&nbsp; I will be bringing new businesses into the online world, and I will need certified blog installers to do the work (you will get paid).&nbsp; Easy as that!&nbsp; If you are interested, go to the link below and sign up for my report on blogging and you will also find out when I am opening up <a target="_blank" href="http://MyBloggingSchool.com">MyBloggingSchool.com</a> for new students!</p>
<p><a target="_blank" href="http://MyBloggingSchool.com">http://MyBloggingSchool.com</a></p>
<p>PPS &#8211; For a limited time I am allowing up to 50 new students to join My Blogging School for a $30 price reduction.&nbsp; I will be doing a webinar with all new users once I have 10 signed up.&nbsp; You can get certified to install a WordPress Blog in two weeks.&nbsp; You must sign up at the <a target="_blank" href="http://extremeproductexplosion.com/blogclass">My Blogging School Blog Installation Certification Course Link</a>.</p>
<p>Technorati Tags: <a class="performancingtags broken_link" href="http://technorati.com/tag/fix%20fantastico%20security%20flaw" rel="tag">fix fantastico security flaw</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/database%20replacement" rel="tag">database replacement</a>, <a class="performancingtags" href="http://technorati.com/tag/new%20user" rel="tag">new user</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/create%20new%20MySQL%20database" rel="tag">create new MySQL database</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/create%20a%20new%20MySQL%20database%20user" rel="tag">create a new MySQL database user</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/assigning%20a%20user%20to%20a%20MySQL%20database%20in%20cpanel" rel="tag">assigning a user to a MySQL database in cpanel</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/exporting%20a%20MySQL%20database" rel="tag">exporting a MySQL database</a>, <a class="performancingtags broken_link" href="http://technorati.com/tag/Importing%20A%20MySQL%20Databse" rel="tag">Importing A MySQL Databse</a></p>
]]></content:encoded>
			<wfw:commentRss>http://michealsavoie.com/welcome/187/fixing-the-fantastico-security-flaw/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

