MySQL.com hacked again
By Tom Brewster,
For the second time in a year, MySQL.com has been hacked and is serving malware.
Security firm Amorize found some highly obfuscated injected JavaScript on the website, noting that visitors would be hit by the BlackHole exploit kit.
“It exploits the visitor's browsing platform ... and upon successful exploitation, permanently installs a piece of malware into the visitor's machine, without the visitor's knowledge,” the company’s co-founder Wayne Huang said in a blog post.
“The visitor doesn't need to click or agree to anything - simply visiting MySQL.com with a vulnerable browsing platform will result in an infection.”
Huang said he was unsure who was behind the attack. Amorize was attempting to contact MySQL.com yesterday, but had not confirmed if the site had responded.
On the KrebsonSecurity blog, Brian Krebs claimed he had found evidence administrative access to MySQL.com was being sold in an “exclusive Russian hacker forum.” The seller went by the name of ‘sourcec0de.’
Worryingly for IT departments, using test site Virus Total, Huang showed only six out of 43 anti-virus engines could detect the malware being served by MySQL.com. When the company first blogged, only four were able to do so.
The video below shows how MySQL.com was serving malware:
MySQL.com was hacked in March 2011, ironically by an SQL injection attack.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





