TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Root access to MySQL.com sold for $3k - now serving malware

173 点作者 michiel3超过 13 年前

10 条评论

pilsetnieks超过 13 年前
From the article: "The ultimate irony of this attack is that the owner of mysql.com is Oracle Corp., which also owns Java, a software suite that I have often advised readers to avoid due to its numerous security and update problems."<p>Seriously, I'm not a fan of Java, but still, a software suite?<p>Anyway, it's quite hard taking that article seriously after that.
评论 #3041134 未加载
评论 #3040813 未加载
评论 #3040822 未加载
ahi超过 13 年前
It seems like they could have done a lot more damage than just serving browser malware. How many mysql installs could they have rooted?
评论 #3040884 未加载
评论 #3041397 未加载
评论 #3040741 未加载
评论 #3041832 未加载
评论 #3041536 未加载
评论 #3041009 未加载
numlocked超过 13 年前
The Armorize screencast embedded in the article is really wonderful. It's concise, full of information, and clear enough to duplicate the steps on your own. A nice 5-minute detective story.
0x12超过 13 年前
This whole mysql saga was an excellent reminder to turn Java off again. I'd enabled it a few weeks ago for a site that I simply had to use and then promptly forgot to disable it afterwards.
评论 #3041262 未加载
ashmud超过 13 年前
Without actually registering on the site to verify, it looks like that's the Exploit.IN forum.
jpdoctor超过 13 年前
I've never seen a $$ number associated with these things, but really? Only $3K?<p>Apparently, I would have overbid if I were in the market for such things.
评论 #3040851 未加载
评论 #3041379 未加载
评论 #3040985 未加载
评论 #3041271 未加载
fragsworth超过 13 年前
Why is it that Flash is so exploitable? The web is rampant with Flash exploits and Adobe seems to do nothing about it.
评论 #3041033 未加载
评论 #3040812 未加载
评论 #3041238 未加载
mkopinsky超过 13 年前
I went to mysql.com this morning and Symantec popped up with a "malware detected" message. Do we know which browsers are vulnerable, and how to tell whether I'm infected?
评论 #3040802 未加载
评论 #3040875 未加载
oblu超过 13 年前
<a href="http://exploit.in/forum/" rel="nofollow">http://exploit.in/forum/</a>
naughtysriram超过 13 年前
Great..! Now nobody will visit MySQL page and the downloads number will do down significantly. Yet another way to kill a community product!!
评论 #3042971 未加载