Root access to MySQL.com sold for $3k - now serving malware
krebsonsecurity.com
krebsonsecurity.com
Seriously, I'm not a fan of Java, but still, a software suite?
Anyway, it's quite hard taking that article seriously after that.
I have always considered it a relatively secure platform... am I so wrong?
Java applets.. shudder
The only reason it doesn't matter server-side is that you are not trying to exploit your own installation. But the bug is still there.
I don't know that there's anything special wrong with it other than that anything deployed widely enough makes a good target.
Edit: here's one sample article from last year:
There were a dozen "unauthorized Operating System takeover including arbitrary code execution" bugs fixed at that time, some exploitable via untrusted applets, others via tricking server installs to submit certain data to standard APIs:
http://www.oracle.com/technetwork/topics/security/javacpujun...
MySQL.com was successfully attacked earlier this year: http://developers.slashdot.org/story/11/03/27/2058246/mysqlc...
(1) Avoid obvious detection in the compromised software?
(2) Put in something that you can actually use for exploits? You have access to many hosts, but how many different configurations are there?
The only thing I can think of is have profiles for several popular packages (e.g. wordpress), and package-specific behavior for them.
If you're running MySQL as root, you're trying hard to get owned.
And even in the more banal sense you interpreted, sure: you might not run mysql.com-sourced daemons as root. But you almost certainly run the mysql command line utility as root from time to time.
So easiest to monetize - insert malware to put trojan on visitors machines. Next - hack in to their bank accounts, or use these as part of bot net or whatever. You basically got highly visited place to put classic malware.
The point is... To do such things as replacing mysql source flawlessly is hard, do not underestimate efforts needed to do that.
Would not the machines rooted with these exploits be likely to be used to log into many mysql installs?
The screenshot shows
http1
http2
http3
with a root shell on each. Are there more than 3? Maybe. Maybe not.
Apparently, I would have overbid if I were in the market for such things.
edit: 12m monthlies, sorry.
you might imagine that no one ever puts such offer on public (or private with everyone having access to it) kind of boards.
its a very usual thing to do, at least, back in the day <strikeout>we</strikeout> they were doing that every time we weren't 200% sure of our tracks or for highly advertised targets (yeah you risk less hacking a whole ISP than you do hacking a nooby site such as mysql.com)
Both Java and Flash. Java was more dangerous, but still...
I don't think I've come across a Java applet in the last 5 years. I see NO need to allow Java in the browser unless it's for a trusted, internal-use application.
https://www.virustotal.com/file-scan/report.html?id=d761babc...