Slashdot Mirror


Mysql.com Hacked, Made To Serve Malware

Orome1 writes "Mysql.com was compromised today, redirecting visitors to a page serving malware. Security firm Armorize detected the compromise through its website malware monitoring platform HackAlert, and has analyzed how the compromise of the site's visitors unfolded. The mysql.com website was injected with a script that generates an iFrame redirecting the visitors to a page where the BlackHole exploit pack is hosted." According to Brian Krebs, the exploit used to compromise the site was being shopped around last week for $3,000.

10 of 81 comments (clear)

  1. Re:I, for one, by Anonymous Coward · · Score: 3, Insightful

    I for one blame poor security.

  2. [generic topic] by Anonymous Coward · · Score: 4, Funny

    little Bobby Tables is disappointed.

  3. No user interaction by Synerg1y · · Score: 3, Interesting

    If the website redirects to an iframe (I thought these got phased out in like HTML4???) and tries to install malware, and there is no user interaction involved... what exactly is the browser doing?

    Being really stupid...
    http://antivirus.about.com/od/virusdescriptions/p/Blackhole-Exploit-Kit.htm

    On that note, noscript, greasemonkey w/ script, and any addon that allows the blocking of the iframe tag should keep you safe, but then again how often do you visit mysql.com? :)

  4. Already Fixed by InvisibleSoul · · Score: 3, Informative
  5. Re:Watch the video on the page, informative by mclearn · · Score: 4, Informative

    I believe it was a multi-tiered attack in that Java, Flash, and PDF exploits were all tried. What is shown in the video is that the Java attack was successful.

  6. Nobody said MySQL was cracked by MacGyver2210 · · Score: 3, Informative

    Someone was shopping around the exploit used to hack the company's website - I am sure it had little to do with MySQL software unless it was an injection that got them access to change the site.

    --
    If the only way you can accept an assertion is by faith, then you are conceding that it can't be taken on its own merits
  7. Obligation by Fnord666 · · Score: 4, Insightful

    The disclosure caught my eye because just a few days ago I saw evidence that administrative access to mysql.com was being sold in the hacker underground for just $3,000.

    At what point should Mr. Krebs have felt some sort of obligation to inform the owners of mysql.com that their root login was being actively shopped?

    --
    'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
    1. Re:Obligation by Anonymous Coward · · Score: 4, Interesting

      As someone who's done ... even... gentle research. I hate to say...I resent the implication of your comment.

      It's mysql, so they aren't exactly a bunch of clowns... but the moment you tell people--you get suspicion thrown on you. If you tell them anonymously, you get *even more* suspicion thrown on you. For further examples, you need only look at the classic tuttle/centos story...
      http://www.theregister.co.uk/2006/03/24/tuttle_centos/ . Now imagine what happens if you /actually/ report a real issue.

      As somebody who feels *fortunate* to have not been investigated in the past due to no small measure of proxy use--I have to say...by asking Krebbs to disclose this, you're asking him to accept undue risk. The last time I reported a /large/ issue with a private server, the server I used was scanned within 50 minutes from IP's originating within the FBI. Sorry... fuck you all--there's no free advice given ever again.

      Quite frankly, other people's problems aren't our job. They nearly aren't our business either save when they lie and advertise they're safe and there's a client curious, or we're looking to spot something... At which point they can pony up for the advice like every other consumer in the market.

      TLDR: There is no obligation. It's at best a generous act of good will that most people really don't deserve anyway.

  8. MySQL hack... by InitHello · · Score: 3, Funny

    I would laugh (hard) if the exploit involved SQL injection.

    --
    If I hadn't been modded down, you'd be reading this right now.
  9. Re:Watch the video on the page, informative by Gutboy · · Score: 3

    Good thing HTML5 won't need all those things to run code on your machine.