Skip to main content

Windows MySQL Worm on the Loose

posted onJanuary 28, 2005
by hitbsecnews

A new worm has been discovered that is targeting MySQL Database servers running on Windows. It seems to have been able to infect a few thousand systems already and like many other similar worms it contacts an IRC server to get commands to go infect some more hosts.
The worm seems to be identified as a version of 'Wootbot' was first identified by the people over at the SANS Internet Storm Center. It uses the "MySQL UDF Dynamic Library Exploit" to compromise the host, however first the worm needs authenticate to the MySQL database server as the 'root'. The worm uses a long list of passwords which are included with the worms code to attempt to brute force the password.

You can find more information about how the worm operates here in the analysis performed by the handlers at SANS. Currently according to the information gathered by SANS a few anti-virus scanners can already pick this up.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th