Windows MySQL Worm on the Loose
A new worm has been discovered that is targeting MySQL Database servers running on Windows. It seems to have been able to infect a few thousand systems already and like many other similar worms it contacts an IRC server to get commands to go infect some more hosts.
The worm seems to be identified as a version of 'Wootbot' was first identified by the people over at the SANS Internet Storm Center. It uses the "MySQL UDF Dynamic Library Exploit" to compromise the host, however first the worm needs authenticate to the MySQL database server as the 'root'. The worm uses a long list of passwords which are included with the worms code to attempt to brute force the password.
You can find more information about how the worm operates here in the analysis performed by the handlers at SANS. Currently according to the information gathered by SANS a few anti-virus scanners can already pick this up.