4 ms·
Exploiting MySQL arbitrary file read: a honeypot that kicks
- chx 8y agoOK this is is fun but can anyone describe a scenario where this is actually dangerous...?
- blunte 8y agoFrom the very entertaining article: Summary A mysql exploit created in two hours can generate ~4 rootshells per month.
- penagwin 8y agoThis is dangerous for anyone who connects to random MySQL databases with the default settings of most clients as it allows arbitrary file reads? The segment at risk is almost exclusively black-hat, although maybe you could MiTM a connection....
- larkeith 8y agoMy immediate thought is if an attacker gains control of your MySQL server they could use this to help propagate across the network (and of course grab arbitrary data from everything that connects).
- tyingq 8y agoNo actual MySQL server is involved in this...
- 13of40 8y agoIt would be interesting to see if the client will upload a file from an SMB share using the credentials the client is running under. But I think the main scenario is where the MySQL server is compromised and the attacker wants to pivot to the client machine.
- roywiggins 8y agomy first thought is, no surprise this is being described by someone with a visibly non-American domain, as this would be a fairly textbook breach of CFAA, right?
- penagwin 8y agoMy understanding (disclaimer, not a lawyer) would be yes this would be a violation. However the group of people who connect to random MySQL servers is going to be almost exclusively black-hat. This would be akin to "But officer he stole my drugs", sure they committed a crime but in reporting it you implicated yourself.
- deleted 8y ago[deleted]
- kevin_thibedeau 8y agoThe connection is initiated by someone who isn't authorized for your server. Don't see anything fraudulent in requesting a file they are free to ignore.
- tantalor 8y agoConsider how happy the district attorney will be if the "someone" in your scenario is a federal agent. I eagerly await your entrapment defense argument.
- kevin_thibedeau 8y agoThey were breaking the law by trying to hack my computer with malicious SQL.
- roywiggins 8y agoThe FBI has not been yet been significantly deterred by courts: https://www.wired.com/2016/05/history-fbis-hacking/ https://www.wired.com/2016/05/history-fbis-hacking/ If they have a search warrant for your server and you hack back, you're liable to have a bad time.
- d33 8y ago> Okay, so what to do with this when I don't want to do any harm? I have contacted abuse@ for the given addresses, but unsurprisingly received no reply. shutdown -h now
- tyingq 8y agoRetrieving the keys and other interesting bits under ~/.ssh might have a higher success rate, and no hash cracking needed.