Malicious Software infected MySQL servers as part of the global DDoS botnet
Symantec has discovered that attackers use malware to hijack the MySQL server, add it to the global DDoS botnet, and then launch a DDoS attack. According to Symantec, attackers can use SQL injection (unconfirmed), use a special UDF (User-Defined Function) file to infect the MySQL server, and then save Downloader on the server. chikdos Trojan.
Since the UDF file allows the MySQL server to start more complex operations, it does not have the access permission to execute common SQL commands. Attackers call the UDF file and then download A more dangerous Trojan named Trojan. Chikdos.. This Trojan is a variant of Trojan. Chikdos malware and is specialized in DDoS attacks.
Symantec recommends that the MySQL server administrator search for dll files with random names in the \ Lib \, \ Lib \ plugin \ and \ Bin \ folders to check whether the MySQL server is infected. Symantec confirmed that the vulnerability is widely used by hackers. Most infected MySQL servers are located in India, China, Brazil, the Netherlands and the United States.
This article permanently updates the link address: