Armenian Knowledge Base  

Go Back   Armenian Knowledge Base > Technical sections > Software > Software Security

LinkBack Thread Tools
Old 28.01.2005, 09:28   #1
Guru Apprentice
Join Date: 02 2002
Location: /dev/null
Age: 44
Posts: 524
Downloads: 0
Uploads: 0
Reputation: 0 | 0
Default MySQL Bot

Most of you probably already aware, but here's the link

In short: Bot trys to guess root password on a MySQL box, then manages to create "app_result.dll" on the local hard drive and then executes it. Infected machine logs into IRC and waits for commands. Affects only Windows machines. It's not a mysql problem, it's a "wrong user, replace and strike any key" problem. Don't put simple root passwords, firewall MySQL ports.

Для тех кто предпочитает русский: Бот "подбирает" рутовкий пароль, создает файл app_result.dll на жестком диске и выполняет его. Зараженная машина "заходит" в IRC и ждет дальнейших указаний. Заражает только МелкоМягкие Окна. Проблемма не в mysql, проблемму следует классифицировать как "wrong user, replace and strike any key".
\/\/h47'5 1n 4 n4m3? 7h47 wh1(h w3 (4|| 4 r053,
8y 4ny 07h3r n4m3 w0u|d 5m3|| 45 5w337...
Reply With Quote

Thread Tools

На правах рекламы:

All times are GMT. The time now is 19:07.

Powered by vBulletin® Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.