I was looking for a file today, i entered the websites ssh user, and while i was searching for the file i searched
find / type f -name "file.php"
i got some permision erros which are normal, but those erros returned all the current mysql users, i believe this shouldn't be possible, a website should not be able to find all users on the database usernames,
find: ‘/var/lib/mysql/user1_****’: Permission denied
find: ‘/var/lib/mysql/user2_****’: Permission denied
find: ‘/var/lib/mysql/user3_****’: Permission denied
find: ‘/var/lib/mysql/user4’: Permission denied
find: ‘/var/lib/mysql/user5_****’: Permission denied
find: ‘/var/lib/mysql/user2_****’: Permission denied
find: ‘/var/lib/mysql/user6_****’: Permission denied
find: ‘/var/lib/mysql/user7_****’: Permission denied
find: ‘/var/lib/mysql/user8_****’: Permission denied
find: ‘/var/lib/mysql/user9_****’: Permission denied
find: ‘/var/lib/mysql/user10_****’: Permission denied
find: ‘/var/lib/mysql/user11_****’: Permission denied
find: ‘/var/lib/mysql/user12_****’: Permission denied
find: ‘/var/lib/mysql/user13_****’: Permission denied
find: ‘/var/lib/mysql/user14_****’: Permission denied
find: ‘/var/lib/mysql/user15_****’: Permission denied
find: ‘/var/lib/mysql/user3_****’: Permission denied
find: ‘/var/lib/mysql/user8_****’: Permission denied