Feeds

MySQL worm attacks Windows servers

Batten down the hatches

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

A worm exploiting vulnerable installations of MySQL to take over Windows servers began spreading across the net yesterday. The MySpooler worm takes advantage of weak administrative passwords to log onto target systems before using the MySQL UDF Dynamic Library exploit to upload malicious code (a backdoor program called Wootbot).

Compromised systems log onto an IRC channel, becoming drones in a zombie network currently programmed to hunt for fresh victims. Intrusion firm PrevX reckons the worm infected 4,500 systems per hour in the early hours of its outbreak, a rapid spread evidenced by an upsurge in port 3306 scans associated with the worm.

The MySQL open source database is available in Unix and Windows flavours but only Windows machines running MySQL 4.0.21 or later are been exploited in the attack. The SANS Institute has put together an analysis of the malware along with suggested defence strategies. Blocking port 3306 on firewalls, restricting access to root accounts and making sure strong passwords resistant to brute force attack are all strongly recommended. ®

Related stories

SQL server worm throttles bandwidth
Security Report: Windows vs Linux
The IT security vuln league table of fear

5 things you didn’t know about cloud backup

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?