On Jan 9, 2012, at 7:27 PM, Reindl Harald wrote:
> Nessus/OpenVAS Test detects the exact server version
> NVT: MySQL Detection (OID: 126.96.36.199.4.1.256188.8.131.52152)
> Overview: MySQL, a open source database system is running at this host.
> MySQL Version '5.5.19-log' was detected on the remote host.
> is there any way to not disclosure the mysqld-version for
> a anonymous connected client?
For the case you give below, no authentication has yet taken place, so you don't know
whether the client is anonymous or not.
But the version is needed for proper client-server negotiation to take place, I believe.
Even if that were not true, any client, anonymous or not, can use SELECT @@version or
SELECT VERSION() to get the version.
> [harry@srv-rhsoft:~]$ telnet localhost 3306
> Trying 127.0.0.1...
> Connected to localhost.
> Escape character is '^]'.
Oracle Corporation / MySQL Documentation Team
Madison, Wisconsin, USA