MySQL Attack Signals 'Bot' Trouble
A "bot" -- a piece of malicious software that can spread and function much like a computer virus Latest News about computer virus or worm -- is seizing on vulnerable MySQL database software running on Windows systems to spread and scan for new victims.
While the MySQL Bot, also known as the Spool CLC, is mitigated by the limited number of Windows machines running MySQL, it managed to infect nearly 10,000 machines with an initial breakout, according to security experts.
The bot was the basis of an advisory from the SANS Institute's Internet Storm Center, which indicated the malware was using the UDF Dynamic Library exploit to attack, employing a "brute force" password-breaking method of entry into systems. Once connected, the bot creates a table, writes an executable into the table, and then creates a MySQL function to load and run itself.