EvilZone

Hacking and Security => Hacking and Security => Topic started by: Satan911 on March 28, 2011, 08:48:57 PM

Title: MySQL.com hacked via... SQL injection vuln
Post by: Satan911 on March 28, 2011, 08:48:57 PM
MySQL.com was hacked over the weekend via an attack which used a blind SQL injection exploit to pull off the pawnage.
Hackers extracted usernames and password hashes from the site, which were subsequently posted to pastebin.com. Any easy to guess login credentials could be easily extracted from this data using rainbow tables to match dictionary passwords to their hash values.

[...]

Article: http://www.theregister.co.uk/2011/03/28/mysql_hack/ (http://www.theregister.co.uk/2011/03/28/mysql_hack/)
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Stackprotector on March 28, 2011, 09:11:32 PM
Almost 1 april right?
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Satan911 on March 28, 2011, 09:58:27 PM
I've seen the database tables / columns.. Will try to find it. (it was in another article)

Edit: Here's a bit more detail: http://www.hackerregiment.com/mysql-com-vulnerable-to-blind-sql-injection.html (http://www.hackerregiment.com/mysql-com-vulnerable-to-blind-sql-injection.html)
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Zesh on March 28, 2011, 10:08:21 PM
MySQL.com was done over by a SQL injection, LOL :P
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: IFailStuff on March 28, 2011, 11:26:59 PM
Maybe it's a fake database that they set up for 1st april? :P
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Stackprotector on March 28, 2011, 11:39:12 PM
Maybe it's a fake database that they set up for 1st april? :P
Very good possibility, as its just to funny to be real:P.
 
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Satan911 on March 28, 2011, 11:57:48 PM
I don't know it seems like a bit risky and it's not even April 1st.
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: I_Learning_I on March 29, 2011, 01:27:16 AM
Has MySQL answered to that? Figures it something like that happened it would be all over the internet in every forums and so.
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Clowner on March 29, 2011, 10:40:50 AM
lol!
Title: Re: MySQL.com hacked via... SQL injection vuln
Post by: Pillus on March 29, 2011, 10:55:33 AM
Oh i smell thy irony! >_<