Results 1 to 8 of 8

Thread: Security flaw CVE-2012-2122 in MySQL

  1. #1
    Join Date
    Dec 2010
    Beans
    573
    Distro
    Ubuntu 12.04 Precise Pangolin

    Security flaw CVE-2012-2122 in MySQL

    Just incase you are not aware of this there is a security flaw (CVE-2012-2122) in the MySQL. This vuerability is based on the way the password hash validation is done. There is a 1 in 256 chance that a bad password will match.

    The vulnerable systems are primarily 64 bit systems.

    Here is a link to more info:
    https://community.rapid7.com/communi...-flaw-in-mysql

  2. #2
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Security flaw CVE-2012-2122 in MySQL

    There are flaws or vulnerabilites in almost all software, you can find a CVE to match most software packages.

    https://cve.mitre.org/

    What is the uniqueness of this particular one ?

    Perhaps i am missing your point ?
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  3. #3
    Join Date
    Nov 2009
    Beans
    919
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Security flaw CVE-2012-2122 in MySQL

    Well there is already a fairly reliable exploit in MSF I think (well, still 1-in-256, but that's better than cracking passwords), but I'm pretty sure the patch was available before then. It's certainly available (and highly recommended) now.

    I suppose there's a pretty convincing argument that MySQL is widely used by people/organizations that are unlikely to patch in a timely manner, which does make it potentially a bigger deal, but yeah, it's really just another vulnerability on the pile.

  4. #4
    Join Date
    May 2010
    Beans
    462
    Distro
    Ubuntu Development Release

    Re: Security flaw CVE-2012-2122 in MySQL

    I don't really care about least i run a server. Using those exploits search engines only reveal known security flaws. I will rather exploit it myself and keep it a secret until someone found it for patch.

  5. #5
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Security flaw CVE-2012-2122 in MySQL

    Quote Originally Posted by wacky_sung View Post
    I don't really care about least i run a server. Using those exploits search engines only reveal known security flaws. I will rather exploit it myself and keep it a secret until someone found it for patch.
    If you have the knowledge to exploit it then you have the knowledge to fix/patch it, so why not contribute rather than wait for someone else.

    The security community is a collaborative one and any true "hacker" (hacker in the TMRC sense) /security researcher shares their knowledge whether zero day or not.
    Last edited by haqking; June 16th, 2012 at 08:40 AM.
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  6. #6
    Join Date
    May 2010
    Beans
    462
    Distro
    Ubuntu Development Release

    Re: Security flaw CVE-2012-2122 in MySQL

    Oh yeah,so true. Just that i rather remain anonymous than make publicity of it. I think i better stay off here since i have already made my statement clear enough.

    http://ubuntuforums.org/showthread.php?t=2004152

  7. #7
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Security flaw CVE-2012-2122 in MySQL

    Quote Originally Posted by wacky_sung View Post
    Oh yeah,so true. Just that i rather remain anonymous than make publicity of it. I think i better stay off here since i have already made my statement clear enough.

    http://ubuntuforums.org/showthread.php?t=2004152

    LOL, yeah so you have the skillset to exploit zero day and to patch it, but not to remain anonymous ?

    anyways moving on swiftly.......
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  8. #8
    Join Date
    Feb 2011
    Beans
    488
    Distro
    Ubuntu

    Re: Security flaw CVE-2012-2122 in MySQL

    Quote Originally Posted by hawkmage View Post
    Just incase you are not aware of this there is a security flaw (CVE-2012-2122) in the MySQL. This vuerability is based on the way the password hash validation is done. There is a 1 in 256 chance that a bad password will match.

    The vulnerable systems are primarily 64 bit systems.

    Here is a link to more info:
    https://community.rapid7.com/communi...-flaw-in-mysql

    From the first article you quoted:

    So far, the following systems have been confirmed as vulnerable:
    Ubuntu Linux 64-bit ( 10.04, 10.10, 11.04, 11.10, 12.04 )
    If you have security updates enabled on your server, would this vulnerability be patched automatically?

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •