[ISN] MySQL Web site falls victim to SQL injection attack

From: InfoSec News <alerts_at_private>
Date: Tue, 29 Mar 2011 00:18:40 -0600 (CST)
http://www.computerworld.com/s/article/9215249/MySQL_Web_site_falls_victim_to_SQL_injection_attack

By Jeremy Kirk
IDG News Service
March 28, 2011

Oracle's MySQL.com customer Web site was compromised over the weekend by 
a pair of hackers who publicly posted usernames, and in some cases 
passwords, of the site's users.

Taking credit for the hack were "TinKode" and "Ne0h," who wrote that the 
hack resulted from a SQL injection attack. They did not provide further 
details. The vulnerable domains were listed as www.mysql.com, 
www.mysql.fr, www.mysql.de, www.mysql.it and www-jp.mysql.com.

According to a post on the Full Disclosure bug mailing list on Sunday, 
MySQL.com ran a variety of internal databases on an Apache web server. 
The information posted included a raft of password hashes, some of which 
have now been cracked.

Among the credentials in a dump of the information posted on Pastebin 
were passwords for a number of MySQL database users on the server, and 
the admin passwords for the corporate blogs of two former MySQL 
employees. The bloggers were former director of product management Robin 
Schumacher, and former vice-president of community relations, Kaj Arnö. 
Schumacher is now director of product strategy at EnterpriseDB, while 
Arnö is now executive vice president for products at SkySQL. 
Schumacher's blog had not been touched since June 2009, Arnö's not since 
January 2010.

[...]


___________________________________________________________      
Tegatai Managed Colocation: Four Provider Blended
Tier-1 Bandwidth, Fortinet Universal Threat Management,
Natural Disaster Avoidance, Always-On Power Delivery 
Network, Cisco Switches, SAS 70 Type II Datacenter. 
Find peace of mind, Defend your Critical Infrastructure.
http://www.tegataiphoenix.com/
Received on Mon Mar 28 2011 - 23:18:40 PDT

This archive was generated by hypermail 2.2.0 : Mon Mar 28 2011 - 23:25:25 PDT