← All guides

MySQL/MariaDB: find possible IP and visitor columns

Requirement

Read-only database access to information_schema; initially do not read content from visitor data tables.

information_schema can reveal tables with names like ip_address, visitor_id, session_id or user_agent. That's a sure first clue. It must then be checked whether and with what the columns are actually filled.

The specific read-only commands are collected under Check the website yourself.

Rate result

A single hit is a technical finding. Then check the purpose, actual storage, transfer and retention period of the affected level separately.

Classify in the overall check

This individual test only covers one level. Then systematically check the remaining levels using the checklist for unnecessary visitor data .

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑