MySQL Site Compromised To Serve Up BlackHole Exploits

  /     /     /  
Publicated : 22/11/2024   Category : security


MySQL Site Compromised To Serve Up BlackHole Exploits


Researchers still analyzing attackers end game



Researchers today discovered that the mysql.com website had been breached and rigged with a script that redirected visitors to a site that serves up malware from the BlackHole crimeware kit. MySQL.com since has cleaned up the site.
Malicious JavaScript code basically redirected visitors browsers to a site hosting the BlackHole exploit pack, unbeknown to the user, according to researchers at Armorize Technologies, who spotted the hacked website and malware. If you go to mysql.com, you would get malware in your system, says Wayne Huang, CTO and a researcher with Armorize Technologies. Im pretty sure we identified it soon after it [went live], he says. MySQL.com fixed it -- they have removed that [malicious] file from the site, he says.
MySQL is a type of open-source database software used by major sites such as Google, Facebook, and Wikipedia, and has some 100,000 page views per day. The site is owned by Oracle.
Huang says BlackHole supports various exploits that go after a variety of vulnerabilities. The malware on MySQL.com modifies the victims Windows DLL files, so its more difficult to detect and eradicate. The victim didnt have to fall for any socially engineered links or pop-ups: Just visiting the site with a vulnerable browser would have gotten them infected, he says.
But as of press time, Huang says its still unclear just what the mysql.com website hackers were after. We dont know what it does [yet], he says.
The issues had now been cleaned up on mysql.com but no further words on the scope of the compromise. It also appears to be the second time this year. In the last incident, SQL injection was used to gain access to the information on the site, blogged SANS Internet Storm Center handler Jason Lam today.
Armorize has posted a video of the attack
here
.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
MySQL Site Compromised To Serve Up BlackHole Exploits