The Register® — Biting the hand that feeds IT

Feeds

MySQL.com hacked via... SQL injection vuln

*facepalm*

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

MySQL.com was hacked over the weekend via an attack which used a blind SQL injection exploit to pull off the pawnage.

Hackers extracted usernames and password hashes from the site, which were subsequently posted to pastebin.com. Any easy to guess login credentials could be easily extracted from this data using rainbow tables to match dictionary passwords to their hash values.

This information revealed that the director of product management for WordPress at MySQL1 used a four digit number as his password, among other snippets, net security firm Sophos reports.

Romanian grey-hat hackers TinKode and Ne0h of Slacker.Ro claimed responsibility for the attack.

MySQL offers open source-based database software and services to enterprises.

Security practices at MySQL.com obviously left quite a lot to be desired. As well as the vulnerability actually used to pull off the attack MySQL.com has been vulnerable to XSS exploits since January, according to XSSed.com.

MySQL's parent company Sun/Oracle was also hit by the same hackers, who extracted emails from compromised websites. Login credentials were not compromised in that case. ®

1 This chap works for MySQL not Wordpress, as incorrectly stated in the first version of this article.

Agentless Backup is Not a Myth

President Skroob

I use the same combination on my luggage!

9
0

Two or three steps above EPIC fail

oh, and the https certificate for the customer.mysql.com domain expired a month ago

7
0

You have totally missed the point

Using a salt renders any 'rainbow tables' completely useless, therefore it is not trivial to automatically extract plaintext passowrds from their hashes in the database.

Also, if the designers of the system have a brain, the salt value will be stored in a file and not in the database itself. To get the salt value would likely require a totally different entry point for the hack. It would most certainly NOT be exposed by a database injection exploit.

Even if the salt value itself is compromised, a new rainbow table would have to be created specially for that particular salt value. While not impossible, it is significantly more hassle and more computationally expensive than using a pre-compiled rainbow table.

Oh, and it is worth noting that Grendel did not actually reveal what his salt value is.

6
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence