Everything is passed plain text, yes. It's also passed plain text when you telnet. The only secure way to log into a server is to use ssh. You can download telnet programs with ssh from tucows.com. There are instructions in the manual for connecting to mysql through ssh, also.
You can issue that command from any dos prompt, as long as your connected to the internet and your mysql server is up, it'll work.
---John Holmes...