Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Worm Hits Windows Machines Running MySQL
/. and SANS ^ | 01/27/2005 | various

Posted on 01/27/2005 6:20:28 PM PST by zeugma

"A report on the Australian whirlpool forum suggest that a worm is currently taking out MySQL servers running on Windows. We have seen this happen with MSSQL before (not just 'Slammer', but also SQLSnake that used SA accounts without password). The SANS Internet Storm Center suggests that a rise in port 3306 scans can be attributed to the new worm, and is asking for observations to help figure this out. It appears the worm creates a file called 'spoolcll.exe'."


TOPICS: Computers/Internet
KEYWORDS: computersecurity; crapware; microsoft; virus; windows; worm
Those of you out there that are running MS-SQL should probably be checking the boxes out extensively for unusual behavior.

Microsoft just announced record earnings again. I guess that's easier when you don't have to worry about debugging your code, or the damage defective products do to clients.

1 posted on 01/27/2005 6:20:28 PM PST by zeugma
[ Post Reply | Private Reply | View Replies]

To: zeugma

This excerpt appears to be about MySQL not MS SQL Server.


2 posted on 01/27/2005 6:23:47 PM PST by Texas_Jarhead (I believe in American Exceptionalism! Do you?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

A good reason to consider PostgreSQL.


3 posted on 01/27/2005 6:24:22 PM PST by ScottM1968
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

You may want to reread this :) . This affects MYSQL, not MS-SQL. Mysql is an open source database --- and its just taking advantage of poorly configured servers, not a flaw in the product itself.


4 posted on 01/27/2005 6:25:03 PM PST by sigSEGV
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

YourSQL?


5 posted on 01/27/2005 6:26:30 PM PST by aomagrat (Where weapons are not allowed, it is best to carry weapons.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

None of my Macs appear to be having any problems.

:-)


6 posted on 01/27/2005 6:56:41 PM PST by 1LongTimeLurker
[ Post Reply | Private Reply | To 1 | View Replies]

To: Texas_Jarhead; sigSEGV; aomagrat
Just damn.

All of you are correct, I misread the thing entirely. I guess I can expect quite a few deserved flamaes. It is definitely a good idea to secure your SQL server better than I proofed the post. :-)

In my defense, MSSQL was mentioned, but only in referring to past vulnerabilities discovered.

7 posted on 01/27/2005 7:31:54 PM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: zeugma

no problem, happens to us all


8 posted on 01/27/2005 7:33:54 PM PST by Texas_Jarhead (I believe in American Exceptionalism! Do you?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: zeugma
Microsoft just announced record earnings again. I guess that's easier when you don't have to worry about debugging your code, or the damage defective products do to clients.

Microsoft announced record earnings again because they have the best products, period. In your haste to spew hate, you didn't even notice this problem is strictly related to another one of your foreign pieces of freeware, MySQL. Must suck to be you about now.

9 posted on 01/27/2005 7:50:10 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 1 | View Replies]

To: Golden Eagle

Everyone gets one free bash as my pennance tonight. That was yours. Have a great evening!


10 posted on 01/27/2005 8:10:57 PM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: aomagrat
YourSQL?

No. HisSQL.

11 posted on 01/27/2005 8:52:24 PM PST by Bloody Sam Roberts (Is it merely a coincidence that ALLAH and SATAN both have five letters in their names?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: zeugma
I posted an article on this tonight. It ended up in the Bloggers/Personal Forum.

MySQL Malware Just Wants to Chat

Unix and Linux systems running MySQL currently are not at risk from the bot.

12 posted on 01/27/2005 9:06:35 PM PST by Eagle9
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
Unix and Linux systems running MySQL currently are not at risk from the bot.

Ya, but the way methods used to hack MySQL might be valid in the Unix world ao care should be taken. Of course, anyone who leaves the default administrator password on their database pretty much deserves to be rooted.

13 posted on 01/27/2005 9:15:33 PM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: zeugma
Of course, anyone who leaves the default administrator password on their database pretty much deserves to be rooted.

LOL !   Yeah, I agree.

14 posted on 01/27/2005 9:21:17 PM PST by Eagle9
[ Post Reply | Private Reply | To 13 | View Replies]

To: zeugma
Ya, but the way methods used to hack MySQL might be valid in the Unix world ao care should be taken.

This was a brute-force method for compromising the servers. Keep strong passwords, and you should be OK.

Basically, what this thing does is keep a list of common passwords and just tries them all until one works. Use non-dictionary, mixed-case, alphanumeric/symbolic passwords and you should be fine.

15 posted on 01/28/2005 5:53:25 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 13 | View Replies]

To: zeugma

MySQL should never have a default password for root and their install should never allow it. Thats just ASKING for a worm.


16 posted on 01/28/2005 5:54:24 AM PST by smith288 ("Bravery is not a reaction to fear but the act of ignoring it from honor.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Golden Eagle
Microsoft announced record earnings again because they have the best products, period

Then by your logic, Apple makes absolutely the best, since they just posted record earnings, quadrupling them in fact. Did Microsoft quadruple its profits?

17 posted on 01/28/2005 12:08:44 PM PST by antiRepublicrat
[ Post Reply | Private Reply | To 9 | View Replies]

To: smith288
MySQL should never have a default password for root and their install should never allow it.

The installer now does ask you for a new password. Earlier ones just defaulted to "root." Still, you're right, it shouldn't be allowed, but I think it's common practice, as MSSQL does it too.

18 posted on 01/28/2005 12:17:13 PM PST by antiRepublicrat
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson