Skip to main content

MySQL Attack Signals 'Bot' Trouble

posted onJanuary 29, 2005
by hitbsecnews

A "bot" -- a piece of malicious software that can spread and function much like a computer virus Latest News about computer virus or worm -- is seizing on vulnerable MySQL database software running on Windows systems to spread and scan for new victims.

While the MySQL Bot, also known as the Spool CLC, is mitigated by the limited number of Windows machines running MySQL, it managed to infect nearly 10,000 machines with an initial breakout, according to security experts.

The bot was the basis of an advisory from the SANS Institute's Internet Storm Center, which indicated the malware was using the UDF Dynamic Library exploit to attack, employing a "brute force" password-breaking method of entry into systems. Once connected, the bot creates a table, writes an executable into the table, and then creates a MySQL function to load and run itself.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th