From SANS NewsBites Vol. 13 Num. 77,
--MySQL Website Compromised; Serves Malware to Visitors (September 26, 2011)
On Monday, September 26, the MySQL website was compromised and was being
used to serve malware. The attack was discovered about 5 AM PDT; the
site was cleaned up several hours later. The JavaScript code known as
the Black Hole exploit kit attempts to launch a series of known browser
attacks against site visitors. Security journalist Brian Krebs noted
that administrative access to the site was being offered last week on
the hacker underground for US $3,000.
http://www.computerworld.com/s/article/9220295/MySQL.com_hacked_to_serve_malware?taxonomyId=17
http://www.theregister.co.uk/2011/09/26/mysql_hacked/
http://krebsonsecurity.com/2011/09/mysql-com-sold-for-3k-serves-malware/
[Editor's Note (Liston): This is the second time in a year that the
MySQL site has been compromised. The first compromise pegged the
ol' irony-meter by reportedly being the result of SQL-injection. No
definitive word yet on the root cause of this latest attack.]
--MySQL Website Compromised; Serves Malware to Visitors (September 26, 2011)
On Monday, September 26, the MySQL website was compromised and was being
used to serve malware. The attack was discovered about 5 AM PDT; the
site was cleaned up several hours later. The JavaScript code known as
the Black Hole exploit kit attempts to launch a series of known browser
attacks against site visitors. Security journalist Brian Krebs noted
that administrative access to the site was being offered last week on
the hacker underground for US $3,000.
http://www.computerworld.com/s/article/9220295/MySQL.com_hacked_to_serve_malware?taxonomyId=17
http://www.theregister.co.uk/2011/09/26/mysql_hacked/
http://krebsonsecurity.com/2011/09/mysql-com-sold-for-3k-serves-malware/
[Editor's Note (Liston): This is the second time in a year that the
MySQL site has been compromised. The first compromise pegged the
ol' irony-meter by reportedly being the result of SQL-injection. No
definitive word yet on the root cause of this latest attack.]



