Get a Pentest and security assessment of your IT network.

News

MySQL Design Flaw Allows Malicious Servers to Steal Files from Clients

A design flaw in the file transfer interaction between a client host and a MySQL server allows an attacker running a malicious MySQL server to get access to any data the connected client has read access to. The problem is with the LOAD DATA statement used with the LOCAL modifier, which is referenced as a security risk in the MySQL documentation. In this case, an attacker can use the flaw to steal the /etc/passwd file, which holds user account records. The same applies with web servers, which act as clients when connecting to a. MySQL server.

Source: https://www.bleepingcomputer.com/news/security/mysql-design-flaw-allows-malicious-servers-to-steal-files-from-clients/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

1 day attack with DDoS booter costs $60 causing $720k in damageSecurity Affairs

News

NSA-linked Cisco exploit poses bigger threat than previously thought