Mysql.com Hacked, Made To Serve Malware
Orome1 writes "Mysql.com was compromised today, redirecting visitors to a page serving malware. Security firm Armorize detected the compromise through its website malware monitoring platform HackAlert, and has analyzed how the compromise of the site's visitors unfolded. The mysql.com website was injected with a script that generates an iFrame redirecting the visitors to a page where the BlackHole exploit pack is hosted."
According to Brian Krebs, the exploit used to compromise the site was being shopped around last week for $3,000.
Blame Oracle.
Someone, a week ago, before anything bad actually happened, was openly selling the fact that mysql was cracked, and anyone seeing the ad knew it, but HackAlert is taking credit for "discovering" the cracking after something bad actually happened?
How about if HackAlert, instead of crawling the web looking for whatever pattern of deviation defines its detection of a hack, crawls the blackhat markets for ads for open access to presumed secure sites.
If they aren't doing that already, and crocking their detection speed...
little Bobby Tables is disappointed.
If the website redirects to an iframe (I thought these got phased out in like HTML4???) and tries to install malware, and there is no user interaction involved... what exactly is the browser doing?
Being really stupid...
http://antivirus.about.com/od/virusdescriptions/p/Blackhole-Exploit-Kit.htm
On that note, noscript, greasemonkey w/ script, and any addon that allows the blocking of the iframe tag should keep you safe, but then again how often do you visit mysql.com? :)
If SQLi took down MySQL there's a pun about "hackception" here somewhere.
http://www.pcworld.com/businesscenter/article/240609/mysqlcom_hacked_to_serve_malware.html Article says the site was already fixed as of 11am PST.
I can only assume that mysql.com was running whatever raw sql queries the browser was submitting, but did you know that you can actually rewrite these to include a semicolon (terminating the query) and then whatever new query you want? Obviously, you can't rely on nobody thinking to do this, and the fact that mysql was hacked is just evidence that you should not expose mysql over the Internet.
If you fail this test: http://java.com/en/download/testjava.jsp
Does that mean you are protected from Java exploits through the browser?
If not, how can you tell? (aside from uninstalling Java altogether)
Thanks!
404 Not Found
MySQL pretends to be an SQL database. That's malware in my book.
It's so virulent that it has infected the minds of a generation of developers, fueling the I Don't Know SQL movement.
I watched the video on the page, showing the step-by-step of the exploit working, and the trace of what it did.
Informative and interesting.
Seems if a person did _not_ have java enabled in their browser, then the attack would have failed.
Uh, Linux geek since 1999.
They should fix this so the site can go back to serving crapware. Ha.
Someone was shopping around the exploit used to hack the company's website - I am sure it had little to do with MySQL software unless it was an injection that got them access to change the site.
If the only way you can accept an assertion is by faith, then you are conceding that it can't be taken on its own merits
Now instead of serving malware directly it redirects to a site serving malware.
The disclosure caught my eye because just a few days ago I saw evidence that administrative access to mysql.com was being sold in the hacker underground for just $3,000.
At what point should Mr. Krebs have felt some sort of obligation to inform the owners of mysql.com that their root login was being actively shopped?
'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
I ain't taking any security certification from them... the MySQL 1&2 was enough.
It was really just a matter of time before Oracle started trying to force MySQL users to move to their expensive proprietary solutions. It just happened a bit....What's that? ........
Oh, NEVERMIND!
I would laugh (hard) if the exploit involved SQL injection.
If I hadn't been modded down, you'd be reading this right now.
... has been hacked by Amazon
slashdot frenzy erupts in 3... 2... 1...
You are so damn right that it ain't funny anymore.
Why is it that this W3C thing is pushing active content upon users, in spite of knowing better.
"Yes, yes, we have a sandbox, therefore we are secure!" is the stupid phrase I'm tired of hearing since the first days of the Java Virtual Machine.
Sandbox, my ass.
What he spotted was a CRIME, perpetrated by foreigners against a US company, therefore he had a duty to report to the FBI cybercrime department. Notifiying the company is miscellanous besides that. I hope Mr. Krebs gets grilled by the FBI, he gets fired from his jobs and the courts will throw him into jail for treason perpetrated against the USA as in being a collaborator and accomplice of foreign criminals. It is a cyberwar already and therefore martial law is a must!
I think organized e-crime should be hunted down the same way as UBL was. Even if they are russian ruffians hiding in a small siberian town to far inland for stealth MH-60 choppers, the B-2 stealth bomber could go in and out unseen and drop a single GPS-guided SDB small-diameter bomb on their safe house with plausible deniability. Maybe a meteorite hit those ruffian hackers, as in heavenly justice? Enough is enough, lets's put the dreaded eavesdropping and geolocating abilities of ECHELON to some good use.
If President-Comrade-Tsar of all ruffians Vladimir Putin complains, disclose the information about how the infamous St. Petersburg RBN cybergang was personally protected by him and have US Navy spec-ops submarines use ROVs to sever the oceanic comms cables linking motherfscker Ruffia to the world. It's not like born criminal anti-semitic slavic nations have a G*d-given right to abuse the judeo-american invented net! hey shall go back to their beloved abacus!
We must recognize the GRAVITY of the hacking and e-crime problem on the net and use the same methods Sir Isaac Newton, head of the Royal Mint, used to end forgery of money and tax evasion in early 1700s London. He did realize the GRAVITY of the problem and had any perpetrators hanged in the streets, quite many foreigners among them. The queen made him a lord for that. Oh, good ol’ morals and laws, where are thou?
Just quit using Mickey$ofts CRAPWARE.
just wanted to make a dirty joke about exposing mysql over the intern but it was lost.
Truth be told it has started with a SQL-injection a few months ago and there was a web-shell available in semi-private access. Just recently the sourcec0de (newly registered member of an underground forum) posted that he sells the root shell for mysql.com. The kernel was pwned with a local exploit. The attacker also claimed that he modified the back-ups which I don't really believe.
Now, that fool who spent $3k and put BlackHole exploit kit directly (well with one redirect) seems to have no understanding of how to convert traffic or what to do with such a valuable item as mysql.com. (next time put backdoors into sources and use TDS before using an exploit kit, n00b)
I mean come on, the malware wasn't FUD (4/34). On a website with this amount of traffic it will be detected (and it was) within hours if not minuets.
This situation shows again that sysadmins shouldn't be lazy and do their jobs... http://www.habrastorage.com/images/msqlrootsa.png screenshot of the forum post.
Mysql serving malware, I don't see how's that news.
The Oracle merger is months old already...
He’s no longer a fetus. Republicans only care about you before you’re born. http://www.coolmonclerclothing.com/