URGENT Security Warning for Windows MySQL Users

 
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions
View previous topic :: View next topic  
Author Message
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Thu Jan 27, 2005 6:17 pm    Post subject: URGENT Security Warning for Windows MySQL Users Reply with quote

Looks like there's some kind of new worm about to go postal on Windows MySQL servers - if you're running one that's accessible to the internet, keep a very close eye on your system until further details are available. Now might be a good time to install a firewall if you don't have one already...

http://forums.whirlpool.net.au/forum-replies.cfm?t=291921
http://isc.sans.org/port_details.php?port=3306&repax=1&tarax=1


Last edited by Anonymoose on Fri Jan 28, 2005 3:15 pm; edited 1 time in total
Back to top View user's profile Send private message
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Fri Jan 28, 2005 3:15 pm    Post subject: Reply with quote

This has now been confirmed. The worm affects 4.0.21 or later servers and affects only servers running on Windows. Remember, if it's only your local machine querying MySQL you don't need the MySQL port open to the internet. If you have chosen to use DMZ on your router rather than specific port forwarding, be extremely careful. The worm attacks weak root passwords.

http://isc.sans.org/diary.php?date=2005-01-27
Back to top View user's profile Send private message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Fri Jan 28, 2005 4:34 pm    Post subject: Reply with quote

So your saying that even if your using v4.0.23 , you cannot be infected if the port 3306 is not
forwarded or open on your router/firewall , I leave my server at localhost so I don't think I
have anything to worry about right , im just curious , I currently have MySQL offline.
Back to top View user's profile Send private message Visit poster's website
olly86
-


Joined: 25 Apr 2003
Posts: 993
Location: Wiltshire, UK

PostPosted: Fri Jan 28, 2005 5:07 pm    Post subject: Reply with quote

If MySQL cannot be accessed from the Internet it cannot be attacked. So from the setup your describing, you are safe.
_________________
Olly
Back to top View user's profile Send private message
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Fri Jan 28, 2005 5:46 pm    Post subject: Reply with quote

That's right.

However, as I know a lot of people gave up on trying to sort out port forwarding on their router and set up their PC in the DMZ instead, it seemed important to mention this...
Back to top View user's profile Send private message
Arctic
-


Joined: 24 Sep 2004
Posts: 560

PostPosted: Fri Jan 28, 2005 10:27 pm    Post subject: Reply with quote

How can I tell if mine is accesible from the internet?
Back to top View user's profile Send private message ICQ Number
kanderson
-


Joined: 25 Jan 2005
Posts: 7
Location: Vancouver, WA

PostPosted: Fri Jan 28, 2005 11:03 pm    Post subject: Reply with quote

If port 3306 is blocked at router level then your MySQL server will only be able to be accessed from within your LAN.

To test this, go to a computer outside of your network that is connected to the Internet.

Go to Start -> Run -> Telnet -> OK

Type: o yourdomain.com 3306

If it responds back, then it's accessable via the net... If it doesn't, then you're clear.
_________________
Kris Anderson
Lead Developer
Zee-Way Services
Back to top View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Moxxnixx
-


Joined: 21 Jun 2003
Posts: 1226
Location: Florida

PostPosted: Sat Jan 29, 2005 8:19 pm    Post subject: 'MySQL bot' database worm is halted Reply with quote

'MySQL bot' database worm is halted
http://www.earthtimes.org/articles/show/1422.html
Back to top View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group