MySQL Servers Hijacked With Malware To Perform DDoS Attacks (symantec.com)
An anonymous reader writes with news of a malware campaign using hijacked MySQL servers to launch DDoS attacks. Symantec reports: "Attackers are compromising MySQL servers with the Chikdos malware to force them to conduct DDoS attacks against other targets. According to Symantec telemetry, the majority of the compromised servers are in India, followed by China, Brazil and the Netherlands, and are being used to launch attacks against an US hosting provider and a Chinese IP address."
So that's like what, three?
"The attackers initially injected a malicious user-defined function (Downloader.Chikdos) into servers" ref
How does this trijan get executed on the host system.
Is there anything I can read about this without disabling NoScript on that bloody Symantec travesty of a website?
Why is your MySQL server directly on the internet?
Paying taxes to buy civilization is like paying a hooker to buy love.
They hijack database servers and use them for DDoS attacks?
That's like breaking into a bank and using its postage meter to send paper spam.
What's WRONG with these people?
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
I'm not a huge fan of Mysql but there's absolutely no context whatsoever to this.
Is this a Mysql 0day that's being used for DDOS once infected?
Does Chikdos brute force a mysql weak password? (which mysql disables all remote access by default)
This seems like a retarded non story that could be used contextually for anything I don't like.
"Shitty configured services are hijacked because of moronic sysadmins" is a better title.
The hackers use SQL injection to insert a user-defined-function that downloads the malware. So, the developers must have been not protecting their strings from SQL injection.
Someone you trust is one of us.
Not everybody’s data is interesting or valueable. If they’re not storing CC#’s or SSN’s, most attackers probably can’t monitize whatever they might find in the DB.
Their bandwidth (assuming an outbound DDoS) or their willingness to pay to keep their systems up (inbound DoS against the company’s other servers) is likely to be far more lucrative than trying to fence their data.
Seriously, who the hell still uses MySQL on DOS servers?
Fight for your bitcoins!
Drones all of them..
like Mindless sheep
All following each other, "eyes and teeth, eyes n teeth"
be that as it may,, this exchange has become lame and wasting time, as we all know DHI loves these exchanges.
over compensation for mayb e *********, **, *.**
but i digress,, waste of time,,
thanks for alowing me to waste time and electricity.
Wow DHI serving something tangable
omg
enough with this, now on with the show
What would you expect, connecting a dead product to the internet?
MySQL died years ago, and lies buried under the heaviest tomb stone in the world, with a six letter inscription "O R A C L E".
Connecting a MySQL server to the internet is like connecting Windows ME to the internet. With file sharing bound to TCP/IP rather than NetBEUI.