«
Expand/Collapse
222 items tagged "mysql"
Related tags:
whitepaper [+],
txt [+],
security vulnerability [+],
security [+],
mdvsa [+],
oracle [+],
sql [+],
malformed [+],
vulnerabilities [+],
ubuntu [+],
remote security [+],
mandriva linux [+],
injection [+],
buffer overflow vulnerability [+],
symbolic link [+],
service [+],
server daemon [+],
red hat security [+],
mysql database server [+],
handler [+],
explain [+],
denial [+],
advanced [+],
denial of service [+],
yassl [+],
uninstall [+],
table [+],
statement [+],
plugin [+],
pdf [+],
null arguments [+],
myisam [+],
local security [+],
data directory [+],
advisory [+],
user [+],
tool [+],
sql injection [+],
security notice [+],
security fixes [+],
rollup [+],
privilege escalation vulnerability [+],
incompatible changes [+],
create [+],
alter database [+],
service vulnerability [+],
yinjector [+],
windows [+],
version [+],
udf user [+],
target system [+],
target host [+],
storage engine [+],
stack buffer [+],
remote file include vulnerability [+],
red [+],
read [+],
proxy support [+],
proof of concept [+],
phpgraphy [+],
penetration [+],
parse [+],
mysql load data [+],
mysql drop [+],
microsoft [+],
local privilege escalation [+],
load data infile [+],
load [+],
insertion [+],
innodb [+],
hacking [+],
format string [+],
exploitation methods [+],
exploitation [+],
eventum [+],
drop [+],
ddl statement [+],
ddl [+],
database [+],
cleanup [+],
brute [+],
Newbie [+],
usn [+],
stack overflow [+],
stack frame [+],
shell [+],
problem [+],
privileges [+],
portuguese [+],
password [+],
mysql socket [+],
multiple threads [+],
make [+],
login attempts [+],
linux security [+],
init script [+],
implementation [+],
flex [+],
faster [+],
exploits [+],
darknet [+],
brute force tool [+],
blind [+],
backdoor [+],
accessible network [+],
Area [+],
vulnerability [+],
remote [+],
mysql server [+],
server [+],
yahoo [+],
video [+],
unspecified [+],
tcp [+],
takeover [+],
ssl certificate [+],
ssl [+],
sql pdf [+],
slides [+],
services menu [+],
server side applications [+],
server certificate [+],
search mode [+],
scanner [+],
rpsa [+],
retired [+],
pywebdav [+],
python script [+],
privilege [+],
port [+],
poc [+],
php [+],
perl [+],
passwords [+],
paper [+],
own computer [+],
overwrite [+],
openssl [+],
mysqlpasswordauditor [+],
mysqld [+],
mysql server through socket [+],
mysql password [+],
mysql command line [+],
mydumper [+],
music [+],
mod [+],
mensa [+],
malware [+],
lookup [+],
logging database [+],
local mysql server through socket [+],
injection bug [+],
html option [+],
html [+],
house [+],
hk music [+],
hijacking [+],
hacked [+],
google [+],
glsa [+],
forcer [+],
escalation [+],
dumper [+],
doing the rounds [+],
dll [+],
directory [+],
db connection [+],
crackbot [+],
computer [+],
command line interface [+],
command line client [+],
command [+],
code execution [+],
character encoding [+],
change [+],
bug [+],
buffer overflow [+],
brute forcer [+],
breach [+],
bench [+],
base web [+],
base [+],
authentication [+],
auth [+],
auditing software [+],
audio [+],
allegedly [+],
admin [+],
access [+],
Pentesting [+],
BackTrack [+],
cve [+],
com [+],
server vulnerability [+],
multiple [+],
bugtraq [+]
-
-
19:07
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1427-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.62 in Ubuntu 10.04 LTS, Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to MySQL 5.0.96. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.
-
-
16:55
»
Packet Storm Security Advisories
Ubuntu Security Notice 1397-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to MySQL 5.0.95. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.
-
16:55
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1397-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to MySQL 5.0.95. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.
-
16:55
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1397-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to MySQL 5.0.95. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.
-
-
14:06
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
14:06
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
14:06
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0127-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. These updated packages upgrade MySQL to version 5.0.95.
-
-
14:26
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
14:26
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
14:26
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0105-01 - MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section.
-
-
15:43
»
Packet Storm Security Recent Files
This is a small MySQL cracking tool capable of running login attempts from multiple threads in parallel. It is capable of 1024 concurrent connections.
-
15:43
»
Packet Storm Security Tools
This is a small MySQL cracking tool capable of running login attempts from multiple threads in parallel. It is capable of 1024 concurrent connections.
-
-
15:30
»
Packet Storm Security Exploits
This Metasploit module creates and enables a custom UDF (user defined function) on the target host via the SELECT ... into DUMPFILE method of binary injection. On default Microsoft Windows installations of MySQL (=
-
15:30
»
Packet Storm Security Recent Files
This Metasploit module creates and enables a custom UDF (user defined function) on the target host via the SELECT ... into DUMPFILE method of binary injection. On default Microsoft Windows installations of MySQL (=
-
15:30
»
Packet Storm Security Misc. Files
This Metasploit module creates and enables a custom UDF (user defined function) on the target host via the SELECT ... into DUMPFILE method of binary injection. On default Microsoft Windows installations of MySQL (=
-
9:01
»
Packet Storm Security Tools
yInjector is a MySQL injection penetration tool. It has multiple features, proxy support, and multiple exploitation methods.
-
-
13:20
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2011-012 - Multiple vulnerabilities has been found and corrected in mysql. storage/innobase/dict/dict0crea.c in mysqld in MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement. MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column. MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier. Various other issues have also been addressed.
-
13:20
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2011-012 - Multiple vulnerabilities has been found and corrected in mysql. storage/innobase/dict/dict0crea.c in mysqld in MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement. MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column. MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier. Various other issues have also been addressed.
-
13:20
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2011-012 - Multiple vulnerabilities has been found and corrected in mysql. storage/innobase/dict/dict0crea.c in mysqld in MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement. MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column. MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier. Various other issues have also been addressed.
-
-
9:02
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1017-1 - It was discovered that MySQL incorrectly handled certain requests with the UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled joins involving a table with a unique SET column. It was discovered that MySQL incorrectly handled NULL arguments to IN() or CASE operations. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled malformed arguments to the BINLOG statement. Various other issues were addressed as well.
-
9:02
»
Packet Storm Security Advisories
Ubuntu Security Notice 1017-1 - It was discovered that MySQL incorrectly handled certain requests with the UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled joins involving a table with a unique SET column. It was discovered that MySQL incorrectly handled NULL arguments to IN() or CASE operations. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled malformed arguments to the BINLOG statement. Various other issues were addressed as well.
-
8:35
»
Packet Storm Security Advisories
Ubuntu Security Notice 1017-1 - It was discovered that MySQL incorrectly handled certain requests with the UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled joins involving a table with a unique SET column. It was discovered that MySQL incorrectly handled NULL arguments to IN() or CASE operations. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled malformed arguments to the BINLOG statement. Various other issues were addressed as well.
-
8:35
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1017-1 - It was discovered that MySQL incorrectly handled certain requests with the UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled joins involving a table with a unique SET column. It was discovered that MySQL incorrectly handled NULL arguments to IN() or CASE operations. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled malformed arguments to the BINLOG statement. Various other issues were addressed as well.
-
8:35
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1017-1 - It was discovered that MySQL incorrectly handled certain requests with the UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled joins involving a table with a unique SET column. It was discovered that MySQL incorrectly handled NULL arguments to IN() or CASE operations. An authenticated user could exploit this to make MySQL crash, causing a denial of service. It was discovered that MySQL incorrectly handled malformed arguments to the BINLOG statement. Various other issues were addressed as well.
-
-
19:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-155 - Multiple vulnerabilities has been found and corrected in mysql. MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service. Additionally many security issues noted in the 5.1.49 release notes have been addressed with this advisory as well.The updated packages have been patched to correct these issues.
-
19:00
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-155 - Multiple vulnerabilities has been found and corrected in mysql. MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service. Additionally many security issues noted in the 5.1.49 release notes have been addressed with this advisory as well.The updated packages have been patched to correct these issues.
-
-
10:00
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-093 - A vulnerability was discovered in mysql which would permit mysql users without any kind of privileges to use the UNINSTALL PLUGIN function. A problem was discovered in the mysqld init script which under certain circumstances could cause the service to exit too quickly, giving the [ OK ] status and before the mysql server was really started and bound to the mysql socket or IP address. This caused a problem for products like Pulse2. The corrected packages solves these problems.
-
10:00
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-093 - A vulnerability was discovered in mysql which would permit mysql users without any kind of privileges to use the UNINSTALL PLUGIN function. A problem was discovered in the mysqld init script which under certain circumstances could cause the service to exit too quickly, giving the [ OK ] status and before the mysql server was really started and bound to the mysql socket or IP address. This caused a problem for products like Pulse2. The corrected packages solves these problems.
-
-
0:49
»
remote-exploit & backtrack
In a PEnTest Scenario we have found a open port for for "3306/tcp open mysql port unauthorized" service .
How we can try to connect it remotely.What more further information we can gain using this information
-
-
8:05
»
remote-exploit & backtrack
Hello all,i'm newbie
I want to set up lamp in backtrack but when i finished , i can't use mysql
when i use mysql command in konsole
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2)
can i help me ,plz ?
Thank for read Thread
-
-
19:21
»
remote-exploit & backtrack
I have created a few BackTrack 4 VM's and set up snort successfully with the BASE and MySQL integration that is configured automatically through the SERVICES menu. However, I have noticed that if I restart my VM, that as soon as I try to go back to localhost/base I get the following message:
Warning: mysql_pconnect() [function.mysql-pconnect]: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2) in /usr/share/php/adodb/drivers/adodb-mysql.inc.php on line 382.
Error (p) connecting to DB: snort@localhost
Check the DB connection variables in base_conf.php
=$alert ...etc.
I have made sure that the alert variables in the base_conf.php file are correct, as I set up two identical VM's and they have the same setup. Both have been restarted, and now I cannot access the BASE web interface.
Is this a known problem perhaps directly related to VMware? Or am I missing something obvious?
Thanks, as any help is greatly appreciated!
-
14:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 897-1 - It was discovered that MySQL could be made to overwrite existing table files in the data directory. It was discovered that MySQL contained a cross-site scripting vulnerability in the command-line client when the --html option is enabled. It was discovered that MySQL could be made to overwrite existing table files in the data directory. It was discovered that MySQL contained multiple format string flaws when logging database creation and deletion. It was discovered that MySQL incorrectly handled errors when performing certain SELECT statements, and did not preserve correct flags when performing statements that use the GeomFromWKB function. It was discovered that MySQL incorrectly checked symlinks when using the DATA DIRECTORY and INDEX DIRECTORY options. It was discovered that MySQL contained a buffer overflow when parsing ssl certificates.
-
17:00
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack buffer overflow in the yaSSL (1.9.8 and earlier) implementation bundled with MySQL. By sending a specially crafted client certificate, an attacker can execute arbitrary code. This vulnerability is present within the CertDecoder::GetName function inside ./taocrypt/src/asn.cpp. However, the stack buffer that is written to exists within a parent function stack frame. NOTE: This vulnerability requires a non-default configuration. First, the attacker must be able to pass the host-based authentication. Next, the server must be configured to listen on an accessible network interface. Lastly, the server must have been manually configured to use SSL. The binary from version 5.5.0-m2 was built with /GS and /SafeSEH. During testing on Windows XP SP3, these protections successfully prevented exploitation. Testing was also done with mysql on Ubuntu 9.04. Although the vulnerable code is present, both version 5.5.0-m2 built from source and version 5.0.75 from a binary package were not exploitable due to the use of the compiler's FORTIFY feature. Although suse11 was mentioned in the original blog post, the binary package they provide does not contain yaSSL or support SSL.
-
17:00
»
Packet Storm Security Exploits
This Metasploit module exploits a stack buffer overflow in the yaSSL (1.9.8 and earlier) implementation bundled with MySQL. By sending a specially crafted client certificate, an attacker can execute arbitrary code. This vulnerability is present within the CertDecoder::GetName function inside ./taocrypt/src/asn.cpp. However, the stack buffer that is written to exists within a parent function stack frame. NOTE: This vulnerability requires a non-default configuration. First, the attacker must be able to pass the host-based authentication. Next, the server must be configured to listen on an accessible network interface. Lastly, the server must have been manually configured to use SSL. The binary from version 5.5.0-m2 was built with /GS and /SafeSEH. During testing on Windows XP SP3, these protections successfully prevented exploitation. Testing was also done with mysql on Ubuntu 9.04. Although the vulnerable code is present, both version 5.5.0-m2 built from source and version 5.0.75 from a binary package were not exploitable due to the use of the compiler's FORTIFY feature. Although suse11 was mentioned in the original blog post, the binary package they provide does not contain yaSSL or support SSL.