Post reply

Name:
Email:
Subject:
Message icon:

Verification:
Type the letters shown in the picture
Listen to the letters / Request another image

Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

shortcuts: hit alt+s to submit/post or alt+p to preview


Topic Summary

Posted by: shellyhowell
« on: 30. April 2011., 07:23:49 »

Wow! shocking news you have shared here.. I think today hacking problem is the main problem in the network.. be careful..
Posted by: Samker
« on: 29. March 2011., 07:24:26 »

 

MySQL.com was hacked over the weekend via an attack which used a blind SQL injection exploit to pull off the pawnage.

Hackers extracted usernames and password hashes from the site, which were subsequently posted to pastebin.com. Any easy to guess login credentials could be easily extracted from this data using rainbow tables to match dictionary passwords to their hash values.

This information revealed that the director of product management for WordPress at MySQL used a four digit number as his password, among other snippets, net security firm Sophos reports: http://nakedsecurity.sophos.com/2011/03/27/mysql-com-and-sun-hacked-through-sql-injection

Romanian grey-hat hackers TinKode and Ne0h of Slacker.Ro claimed responsibility for the attack.

MySQL offers open source-based database software and services to enterprises.

Security practices at MySQL.com obviously left quite a lot to be desired. As well as the vulnerability actually used to pull off the attack MySQL.com has been vulnerable to XSS exploits since January, according to XSSed.com.

MySQL's parent company Sun/Oracle was also hit by the same hackers, who extracted emails from compromised websites. Login credentials were not compromised in that case.


(ElReg)
Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising