HomepageDirectoryGuideBlog

Remortgages

Search

Create the future you want! Learn to make money online. Visit our website and start today!  www.exclusivebizopps.com

US-CERT Alert: MySQL UDF Worm

US-CERT is aware of a new attack vector being used by the "Wootbot/Spybot" tool. This variant is currently being identified as the "MySQL UDF Worm". This variant compromises MySQL servers on the Microsoft Windows platform with weak or null passwords.
Once the bot tool compromises a vulnerable server, it utilizes the User Defined Function (UDF) capability of MySQL to install a function that downloads a variant of "Wootbot/Spybot". The compromised server then attempts to contact a Command and Control (C&C) server and will scan for other vulnerable systems on port 3306/TCP. It may be possible to protect against this specific attack by blocking inbound traffic to port 3306/TCP at the network perimeter.

As of release 4.1.5 gamma, the application now requires the password to be changed upon installation. However, some releases prior to 4.1.5 did not require a password change. Other applications that utilize MySQL may also be vulnerable to this attack vector if they install MySQL with a weak or null password.

More information about this issue is available in the MySQL security alert. You may also wish to visit the US-CERT's computer virus resources page. US-CERT is continuing to investigate this incident.

[ Comment, Edit or Article Submission ]

Share this:

Add To Slashdot Stumble This Digg This Add To Del.icio.us Add To Reddit Add To Yahoo MyWeb Add To Google Bookmarks Add To Furl Fav This With Technorati Add To Newsvine Add To Bloglines Add To Ask Add To Windows Live

More about:

Dec January 2009 Feb
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Remortgages Blog on Technorati Related Blog of Remortgages on Sphere