(1) Avoid obvious detection in the compromised software?
(2) Put in something that you can actually use for exploits? You have access to many hosts, but how many different configurations are there?
The only thing I can think of is have profiles for several popular packages (e.g. wordpress), and package-specific behavior for them.
So easiest to monetize - insert malware to put trojan on visitors machines. Next - hack in to their bank accounts, or use these as part of bot net or whatever. You basically got highly visited place to put classic malware.
The point is... To do such things as replacing mysql source flawlessly is hard, do not underestimate efforts needed to do that.
MySQL.com was successfully attacked earlier this year: http://developers.slashdot.org/story/11/03/27/2058246/mysqlc...
The screenshot shows
http1
http2
http3
with a root shell on each. Are there more than 3? Maybe. Maybe not.
Would not the machines rooted with these exploits be likely to be used to log into many mysql installs?
If you're running MySQL as root, you're trying hard to get owned.
And even in the more banal sense you interpreted, sure: you might not run mysql.com-sourced daemons as root. But you almost certainly run the mysql command line utility as root from time to time.