4.2 Ensure Example or Test Databases are Not Installed on Production Servers

Information

The default MySQL installation does not contain any example or test databases. However, it is a good idea to review for common example databases and ensure they have been removed from production systems.

Dropping example databases will reduce the attack surface of the MySQL server.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Execute the following SQL statement to drop an example database:

DROP DATABASE <database name>;

See Also

https://workbench.cisecurity.org/benchmarks/20915

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: MySQLDB

Control ID: f4beca7c829abd69b0a7c713450eeb9bb6cd23ef3597da2daa2b5c6447c45b7b