An email was sent out earlier today on the Full-Disclosure mailing list, detailing the compromise of numerous MySQL websites along with portions of their database containing usernames and passwords.

MySQL offers database software and services for businesses at an enterprise level as well as services for online retailers, web forums and even governments. The vulnerability for the attack, completed using blind SQL injection and targeted servers including MySQL.com, MySQL.fr, MySQL.de and MySQL.it, was initially found by "TinKode" and "Ne0h" of Slacker.Ro (according to their pastebin.com/BayvYdcP dump of the stolen credentials) but published by "Jackh4x0r".
The stolen database contain both member and employee email addresses and credentials, as well as tables with customer and partner information and internal network details. Hashes from the database have been posted, with some having been already cracked.
A submission to XSSed.com also details an XSS (Cross Site Scripting) vulnerability affecting MySQL.com that may have provided a secondary entry point for compromising visitors or employees with the organization since early January of 2011.
This is definitely a shame for the folks behind MySQL since they were bought by Sun and later on by Oracle (through the Sun acquisition). MySQL is used by millions of users for small and medium sized databases, including by the popular blogging software WordPress.
The email sent to Full Disclosure lists out all the databases, tables and even some password hashes for the users at MySQL.com. There has been no response from MySQL on this issue yet. We have contacted them for a comment and will update this post once more information becomes available.
More updates coming soon….
Update: This hack also compromised the database at Sun.com, more info on this at http://tinkode27.baywords.com/




Pingback: MySQL.com Database Compromised By Blind SQL Injection » Musings on Database Security
Pingback: LMFAO! MySQL.com Compromised By SQL Injection | jessecurry
Pingback: Follia Digitale » MySQL.com vittima di SQL Injection
Pingback: irony « a blodg
Pingback: SQL injections and cross-site scripting - Aetheric Research, Ltd.
Pingback: MySQL Compromised by SQL Injection « A Geek With Guns
Pingback: Site oficial do MySQL é invadido usando… SQL Injection | Global
Pingback: » links for 2011-03-28 (Dhananjay Nene)
Pingback: Site oficial do MySQL é invadido usando SQL Injection | Eder Freire
Pingback: Episode 352 – IPv6 DoS, $IPv4, EU, MySQL, Dumpster Diving, BofA & SCADA | InfoSec Daily
Pingback: Episode 352 – IPv6 DoS, $IPv4, EU, MySQL, Dumpster Diving, BofA & SCADA » ä¿¡æ¯å®‰å…¨æ’客
Pingback: Site do banco de dados MySQL sofre invasão hacker | Rotina Digital
Pingback: Hackeado el sitio de MySQL usando su herramienta | Incubaweb
Pingback: MySQL.com Database Compromised By Blind SQL Injection « Hornet Dear Bernard
Pingback: Ironic Hacking? mysql.com was pwned via SQL Injection. – The Category5.TV Newsroom