UPDATED 21:35 EDT / JANUARY 21 2019

SECURITY

MySQL database management vulnerability opens the door to data theft

A flaw in the highly popular MySQL database management system can allow malicious servers to steal files from clients.

First reported by Security Boulevard Friday and then picked up in more detail today by Bleeping Computer, the design flaw was found in the file transfer interaction between a client host and a MySQL server. The flaw allows an attacker running a malicious MySQL server to get access to any data to which the connected client has read access.

Allegedly that can be leveraged to retrieve sensitive information from an improperly configured web server that allows connections to untrusted servers, or from database management applications. The issue is said to lie with the LOAD DATA statement used with the LOCAL modifier, which the MySQL documentation references as a security risk.

In an interesting twist, a discussion on Reddit claims that the same MySQL flaw is how the Magecart hacking group attacks have been so successful. In those attacks, a hacking group inserted code to intercept payment transactions across multiple sites. Known successful Magecart attacks include Newegg Inc., the Infowars StoreCathay Pacific Airways Ltd., British AirwaysTicketmaster Entertainment Inc. and Oxo International Ltd.

Craig Young, computer security researcher for Tripwire Inc.’s Vulnerability and Exposure Research Team, told SiliconANGLE that although this latest vulnerability may not sound critical, since most users are not easily fooled into connecting to an attacker’s MySQL server, there are in fact many web servers with exposed database management interfaces that allow attacker-initiated connections to arbitrary servers.

“Website administrators must be aware that such pages, even when not linked to other content, may be discovered and abused by attackers,” he said. “Administration tools like Adminer should not be left unprotected in any circumstances.”

Photo: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.