Tuesday, March 29, 2011

MySQL.com victim of SQL injection

Fills out the awkwardness of certain directors and MySQL. com was hacked last weekend by a SQL injection. The hackers were able to extract usernames and passwords footprints they have not failed to post on pastebin. com. Two Romanian hackers have claimed the act with the release of identifiers on the Internet.

Hackers have also attempted to use the same attack on the Oracle site, but they left empty-handed. They were nevertheless able to decrypt passwords using simple table rainbow sky that can find a password from its footprint. Thus the world has discovered that the director responsible for the account in Wordpress MySQL used only as a four-digit password (the code of his bank card?).

MySQL. com hosts the popular tool for MySQL database. It also offers tips to ensure the security of the database. Hackers claim nevertheless have published one month before the flaw to exploit. It is recommended to all who have an account on MySQL. com change password. If the scope of the problem is minimal, the irony of the situation should remain in the annals.

MySQL also continues to be vulnerable to cross-site scripting attacks, according to Sophos, which are known from the beginning of the year. As a reminder, this kind of attack can inject arbitrary data into a web site to modify its operation. For example, publish a message on the forum that will contain malicious code that will run the site.

No comments:

Post a Comment