MySQL Bot Attacks Windows Systems

Martin

Deceased
MySQL Bot Attacks Windows Systems
by Julio Franco on Fri 28 Jan 2005, 07:00 PM
According to reports from eWeek and various other sources, malicious hackers have launched a zero-day bot attack against Windows servers using the MySQL database engine, infecting vulnerable systems at the rate of 100 per minute.

The bot attack consists of authenticating into the server as root and then pulling the password using the brute-force method using a list of passwords included with the bot.

The bot takes advantage of the publicly released "MySQL UDF Dynamic Library Exploit" to break into the open-source MySQL package. Once a database is hijacked, infected systems will connect to an IRC (Internet Relay Chat) server and retrieve propagation instructions.


http://www.techspot.com/story16869.html
 

OddOne

< Yes, I do look like that.
Those of us that run MySQL on development machiens may want to ensure that their servers aren't exposed to the world. I run the Apache/MySQL/PHP combo on WinXP for localized web development, and have all of the normally-exposed ports are blocked at my router.

Those of us that run MySQL backended websites need to watch this one closely.

oO
 
Top