Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE
MySQL protocol design flaw and attack

CoreLabs Technical Report (Note: Advisory CVE-2000-0981 describes the same vulneability)

Abstract

The MySQL challenge and response authentication protocol is proven insecure. Sensitive information is shown to be leaked during each execution of this protocol. We present an algorithm exploiting this vulnerability that enables a passive attacker to impersonate a valid user after witnessing a small number of protocol executions.
The paper concludes with statistical information and some effciency and effectiveness estimates.

Related Content