Researchers today discovered that the mysql.com website had been breached and rigged with a script that redirected visitors to a site that serves up malware from the BlackHole crimeware kit. MySQL.com since has cleaned up the site.
MySQL is a type of open-source database software used by major sites such as Google, Facebook, and Wikipedia, and has some 100,000 page views per day. The site is owned by Oracle.
Huang says BlackHole supports various exploits that go after a variety of vulnerabilities. The malware on MySQL.com modifies the victims' Windows DLL files, so it's more difficult to detect and eradicate. The victim didn't have to fall for any socially engineered links or pop-ups: Just visiting the site with a vulnerable browser would have gotten them infected, he says.
But as of press time, Huang says it's still unclear just what the mysql.com website hackers were after. "We don't know what it does [yet]," he says.
"The issues had now been cleaned up on mysql.com but no further words on the scope of the compromise. It also appears to be the second time this year. In the last incident, SQL injection was used to gain access to the information on the site," blogged SANS Internet Storm Center handler Jason Lam today.
Armorize has posted a video of the attack here.
Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio