Hackers Use MIT Server to Hack 100,000 Sites
November 7, 2011 2:42 PM
Nearly five months of attacks went unnoticed and successful thanks to the MIT domain's strong reputation
Most content-heavy sites on the web today are driven by a mix of PHP and SQL. Unfortunately, exploits abound from popular PHP database manager frontends like PHPMyAdmin. Thus, "hacking" many websites has been reduced from an art down to a "brute force" search for applicable SQL vulnerabilities [
]. And that's just was cybercriminals want.
In this bold new world of SQL injection having a reliable host for your "brute force" attack web-crawler program is essential. A recent incident involving an infected server at the
Massachusetts Institute of Technology
shows how *.edu servers may be the perfect vehicle to carry out cybercriminals' attacks.
The MIT server had the perfect profile to carry out attacks. It had bandwidth aplenty. And it piggybacked on its school's strong reputation, making its requests automatically appear trusted and less suspicious.
MIT's campus [Source: Aisha]
Thus it's not surprising that once a malicious softbot was planted on the MIT server that it was able to wreak havoc on the internet for nearly six months.
The attacking server was identified by Bitdefender, the antimalware arm of Romanian-based software firm Softwin. It is unknown how the malicious software was planted on the server. What is clear is what the attacking software has been doing.
The attacking server (CSH-2.MIT.EDU) would locate webpages and initiate a set of SQL injection attempts using GET requests and certain characters troublesome sequences like "//". An example is seen below in the
"GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1"
"GET /muieblackcat HTTP/1.1" 404 "GET //scripts/setup.php HTTP/1.1" 301
"GET //admin/scripts/setup.php HTTP/1.1"
"GET //admin/pma/scripts/setup.php HTTP/1.1" 404
"GET //admin/phpmyadmin/scripts/setup.php HTTP/1.1" 404
"GET //db/scripts/setup.php HTTP/1.1" 404
These attempts targeted vulnerabilities in PHPMyAdmin versions 2.5.6 to 2.8.2. PHPMyAdmin is an open source frontend that
at the popular software repository SourceForge. It has an impressive 50k+ downloads a week. The latest version is 3.4.7.
The attacks compromised a reported 100,000+ websites in the five months since the MIT server was compromised in June.
The script would use injection attempts to deface pages, dumping keywords on them that would elevate their page rank. It would also dump images from BlogSpot, DeviantART, and Tumblr, among others, on the front-page.
Over 100,000 webpages were compromised by the rogue MIT server. [Source: SecurityWeek]
The telltale sign of the compromised pages was a directory "muieblackcat", which was created on the victims' server space.
For now the attack has been silenced, but it serves as a warning of the growing dangers of SQL injection attacks and the potential of abuse of trusted *.edu servers.
wrote a piece
on the attacks, suggest implementing anti-injection rewrite rules/conditionals and to rename your PHPMyAdmin script to prevent quick identification from casual attackers.
"Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine." -- Bill Gates
Nokia is the Victim of SQL Injection, Loses Developer Records
August 29, 2011, 8:37 AM
LulzSec Strikes Again, 1M Sony Pictures User Accounts Compromised
June 2, 2011, 6:27 PM
Sony Loses Yet More Customer Records, 3 More Sites Hacked
May 25, 2011, 8:16 AM
Sony Appears to Have Lost Yet Another User Database
May 23, 2011, 9:09 AM
Pirate Bay Hacked, 4 Million User Records Looted, Site Is Down
July 8, 2010, 10:31 AM
Google plans ultra-fast wireless Internet for Research Triangle Park, N.C.
August 12, 2016, 6:30 AM
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
CNN Resorts to Internet Censorship to Promote Clinton Over Senator Sanders
October 15, 2015, 2:47 PM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Most Popular Articles
Apple iOS Contains Secret One-handed Keyboard Code
October 22, 2016, 5:00 AM
The Unlocked Moto Z Play Launches for $449.99 Today.
October 22, 2016, 5:00 AM
The New HP Spectre: Revamped and Ready
October 23, 2016, 6:00 AM
New Way to Read Data on Ulta Hard Drives
October 23, 2016, 9:38 AM
Car Insurance - The Hidden Discriminatory Practise
October 18, 2016, 5:00 AM
Latest Blog Posts
From Time to Time, The Unbelievable and Unimaginable Happens!!!!
Oct 28, 2016, 4:56 AM
Key EpiPen Competitor Out in 2017 At ' Very Low' Cost
Oct 27, 2016, 5:30 AM
Researchers use CRISPR to Accelerate Search for HIV Cure
Oct 26, 2016, 5:00 AM
Medical Council of India Makes Generic Medicines Mandatory
Oct 25, 2016, 5:00 AM
MacBoo Pro 2016: Release date Oct. 27
Oct 24, 2016, 7:16 AM
Mac Users, Try this if Your Mac is Infected?
Oct 23, 2016, 7:00 AM
Tips to Prevent Smartphones From Overheating:
Oct 22, 2016, 5:00 AM
Nasa Flies Drones at Nevada Airport
Oct 21, 2016, 8:21 AM
T-Mobile Data Problems
Oct 20, 2016, 10:17 AM
Annoying Apple Watch Problems and How to Fix Them
Oct 20, 2016, 5:00 AM
Your Mail May Soon Be Delivered By Robot
Oct 19, 2016, 9:34 AM
2018 Jeep Wrangler Prototype Sells At Junkyard
Oct 18, 2016, 5:00 AM
Samsung Shines with Gold Edition Tablet
Oct 17, 2016, 9:24 AM
Tesla Hints Mysterious Product Debut for October 17th
Oct 16, 2016, 10:14 AM
Samsung Galaxy Note 7 Phones on US flights
Oct 15, 2016, 5:00 AM
Comcast Fined $2.3 Million For Unconfirmed Services Charged To Customers
Oct 14, 2016, 5:00 AM
“American singer / songwriter “Bob Dylan is awarded 2016 Nobel Prize in Literature.
Oct 13, 2016, 10:33 AM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information