Automated bot attacks MySQL database
Automated bot attacks MySQL database
R E L A T E D   C O N T E N T
ADVERTISEMENT

Bot infects thousands of MySQL PCs

Popular database vulnerable to newly discovered attack

Robert Jaques, vnunet.com 28 Jan 2005
ADVERTISEMENT

Security experts have discovered a malicious automated bot designed to attack and take over vulnerable installations of the popular MySQL database running on Windows.

According to a warning from the Internet Storm Center (ISC) on the website of IT security watchdog SANS Institute, the bot has infected a "few thousand systems so far". The ISC identified it as a version of 'Wootbot'.

"It appears to include the usual set of bot features, like a distributed denial of service engine, various scanners, and commands to solicit information from infected systems (e.g. system stats, software registration keys and such). The bot provides an FTP server and a backdoor," said the ISC.

The bot uses the 'MySQL UDF Dynamic Library Exploit', but in order to launch this exploit the malicious code has to authenticate to MySQL as a 'root' user and contains a long list of words to execute brute force password attacks.

"Once connected, the bot will create a table called 'bla' using the database 'mysql', which is typically used to store administrative information like passwords, and is part of every MySQL install. The only field in this database is a binary large object named 'line'," the ISC warning stated.

"Once the table is created, the executable is written into the table using an insert statement. The content is then written to a file called 'app_result.dll' using 'select * from bla into dumpfile app_result.dll'. The 'bla' table is dropped once the file is created."

After successfully infecting a system, the bot attempts to connect to one of several IRC servers on port 5002 or 5003 using dynamic DNS so that the IP addresses are not constant.

IT and network managers are advised to set a strong password on the root account, restrict access to root as much as is practically possible and apply firewall rules to block ports used by the malicious code.

A one page cheat-sheet explaining how to set up passwords and disable network access in MySQL can be downloaded from the SANS Institute here.

See also:

Deal for better integration of both firms' software  21 Apr 2005
Lem BingleySome widely adopted security measures don't do much for user confidence  03 Feb 2005
The arrival of the true computer parasite  17 Jan 2005
Increasing automation and sophisticationAnti-Phishing Working Group reports 'disturbing' new trend  24 Nov 2004
Remotely controlled computersSymantec reports up to 75,000 PCs being compromised daily  20 Sep 2004

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Solihull, United Kingdom | Enzen Global Limited
 Business Consultant - £35,000 - £40,000 - Solihull We are in need of a Business Consultant with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
CMS Engineer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
Central London, United Kingdom | MI5 Security Service
Experienced UNIX Developer - Up to £50,000 + benefits -Central London As an experienced UNIX Developer, you will be responsible for product development, integration, configuration and evaluation on UNIX and .net platforms. You will have ... more >
Central London, United Kingdom | Royal Academy of Music
Head of Technology - London - Competitive salary & benefits The Head of Technology will lead and direct the Academy's Technology department, working with Senior Management to define and implement the IT strategy. The postholder ... more >
More job opportunities