TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Root access to MySQL.com sold for $3k - now serving malware

173 pointsby michiel3over 13 years ago

10 comments

pilsetnieksover 13 years ago
From the article: "The ultimate irony of this attack is that the owner of mysql.com is Oracle Corp., which also owns Java, a software suite that I have often advised readers to avoid due to its numerous security and update problems."<p>Seriously, I'm not a fan of Java, but still, a software suite?<p>Anyway, it's quite hard taking that article seriously after that.
评论 #3041134 未加载
评论 #3040813 未加载
评论 #3040822 未加载
ahiover 13 years ago
It seems like they could have done a lot more damage than just serving browser malware. How many mysql installs could they have rooted?
评论 #3040884 未加载
评论 #3041397 未加载
评论 #3040741 未加载
评论 #3041832 未加载
评论 #3041536 未加载
评论 #3041009 未加载
numlockedover 13 years ago
The Armorize screencast embedded in the article is really wonderful. It's concise, full of information, and clear enough to duplicate the steps on your own. A nice 5-minute detective story.
0x12over 13 years ago
This whole mysql saga was an excellent reminder to turn Java off again. I'd enabled it a few weeks ago for a site that I simply had to use and then promptly forgot to disable it afterwards.
评论 #3041262 未加载
ashmudover 13 years ago
Without actually registering on the site to verify, it looks like that's the Exploit.IN forum.
jpdoctorover 13 years ago
I've never seen a $$ number associated with these things, but really? Only $3K?<p>Apparently, I would have overbid if I were in the market for such things.
评论 #3040851 未加载
评论 #3041379 未加载
评论 #3040985 未加载
评论 #3041271 未加载
fragsworthover 13 years ago
Why is it that Flash is so exploitable? The web is rampant with Flash exploits and Adobe seems to do nothing about it.
评论 #3041033 未加载
评论 #3040812 未加载
评论 #3041238 未加载
mkopinskyover 13 years ago
I went to mysql.com this morning and Symantec popped up with a "malware detected" message. Do we know which browsers are vulnerable, and how to tell whether I'm infected?
评论 #3040802 未加载
评论 #3040875 未加载
obluover 13 years ago
<a href="http://exploit.in/forum/" rel="nofollow">http://exploit.in/forum/</a>
naughtysriramover 13 years ago
Great..! Now nobody will visit MySQL page and the downloads number will do down significantly. Yet another way to kill a community product!!
评论 #3042971 未加载