Hackers Use MIT Server to Hack 100,000 Sites
November 7, 2011 2:42 PM
Nearly five months of attacks went unnoticed and successful thanks to the MIT domain's strong reputation
Most content-heavy sites on the web today are driven by a mix of PHP and SQL. Unfortunately, exploits abound from popular PHP database manager frontends like PHPMyAdmin. Thus, "hacking" many websites has been reduced from an art down to a "brute force" search for applicable SQL vulnerabilities [
]. And that's just was cybercriminals want.
In this bold new world of SQL injection having a reliable host for your "brute force" attack web-crawler program is essential. A recent incident involving an infected server at the
Massachusetts Institute of Technology
shows how *.edu servers may be the perfect vehicle to carry out cybercriminals' attacks.
The MIT server had the perfect profile to carry out attacks. It had bandwidth aplenty. And it piggybacked on its school's strong reputation, making its requests automatically appear trusted and less suspicious.
MIT's campus [Source: Aisha]
Thus it's not surprising that once a malicious softbot was planted on the MIT server that it was able to wreak havoc on the internet for nearly six months.
The attacking server was identified by Bitdefender, the antimalware arm of Romanian-based software firm Softwin. It is unknown how the malicious software was planted on the server. What is clear is what the attacking software has been doing.
The attacking server (CSH-2.MIT.EDU) would locate webpages and initiate a set of SQL injection attempts using GET requests and certain characters troublesome sequences like "//". An example is seen below in the
"GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1"
"GET /muieblackcat HTTP/1.1" 404 "GET //scripts/setup.php HTTP/1.1" 301
"GET //admin/scripts/setup.php HTTP/1.1"
"GET //admin/pma/scripts/setup.php HTTP/1.1" 404
"GET //admin/phpmyadmin/scripts/setup.php HTTP/1.1" 404
"GET //db/scripts/setup.php HTTP/1.1" 404
These attempts targeted vulnerabilities in PHPMyAdmin versions 2.5.6 to 2.8.2. PHPMyAdmin is an open source frontend that
at the popular software repository SourceForge. It has an impressive 50k+ downloads a week. The latest version is 3.4.7.
The attacks compromised a reported 100,000+ websites in the five months since the MIT server was compromised in June.
The script would use injection attempts to deface pages, dumping keywords on them that would elevate their page rank. It would also dump images from BlogSpot, DeviantART, and Tumblr, among others, on the front-page.
Over 100,000 webpages were compromised by the rogue MIT server. [Source: SecurityWeek]
The telltale sign of the compromised pages was a directory "muieblackcat", which was created on the victims' server space.
For now the attack has been silenced, but it serves as a warning of the growing dangers of SQL injection attacks and the potential of abuse of trusted *.edu servers.
wrote a piece
on the attacks, suggest implementing anti-injection rewrite rules/conditionals and to rename your PHPMyAdmin script to prevent quick identification from casual attackers.
"We shipped it on Saturday. Then on Sunday, we rested." -- Steve Jobs on the iPad launch
Nokia is the Victim of SQL Injection, Loses Developer Records
August 29, 2011, 8:37 AM
LulzSec Strikes Again, 1M Sony Pictures User Accounts Compromised
June 2, 2011, 6:27 PM
Sony Loses Yet More Customer Records, 3 More Sites Hacked
May 25, 2011, 8:16 AM
Sony Appears to Have Lost Yet Another User Database
May 23, 2011, 9:09 AM
Pirate Bay Hacked, 4 Million User Records Looted, Site Is Down
July 8, 2010, 10:31 AM
Science & Environment
February 20, 2017, 6:37 AM
The USA’s newest weather satellite sends first photos.
January 24, 2017, 6:41 AM
Netflix took a decision to invest in original content
January 19, 2017, 7:00 AM
Amazon Airborne Fulfillment Center – Your Merchandise Drop-Shipped from the Clouds
December 29, 2016, 5:00 AM
Amazon is experimenting with a new kind of grocery stores, Amazon Go
December 8, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Most Popular Articles
Surface Pro 5 Rumors - New Release Date and Price
April 22, 2017, 6:45 AM
Apple Watch NikeLab Limited Edition unveiled.
April 22, 2017, 6:20 AM
SAPPHIRE PULSE Radeon RX 580 8GD5 – Great Value for the Money
April 20, 2017, 7:47 AM
Meet the Smartphone with four cameras - Alcatel Flashphone
April 5, 2017, 11:20 AM
Dell Inspiron 17 7000 – A Premium Laptop featuring 7th Gen Intel Core i7 in a 2-in-1 Frame.
April 19, 2017, 7:45 AM
Latest Blog Posts
Galaxy Note 8 – Available Second Half 2017
Apr 28, 2017, 7:30 AM
Google Android App – Huge improvement on Nighttime Photography
Apr 27, 2017, 7:40 AM
Google Co-Founder, Sergey Brin has an Airship
Apr 26, 2017, 6:43 AM
Samsung Galaxy S8 and S8 Plus – Lots of Glass that Breaks Easily
Apr 25, 2017, 7:20 AM
Samsung Galaxy S8 – Warning for Pet Owners
Apr 24, 2017, 5:59 AM
Sound Bars and the Costs?
Apr 23, 2017, 6:30 AM
Link your Brain to Your Computer – In Four Years…Maybe
Apr 22, 2017, 7:03 AM
Google Home can now identify users by their voice.
Apr 21, 2017, 7:15 AM
Amazon Lex – Now Available for Developers.
Apr 20, 2017, 6:58 AM
You can now use Instagram offline on your Android Smartphone
Apr 19, 2017, 8:00 AM
Now you can livestream to YouTube from your mobile device.
Apr 18, 2017, 8:05 AM
Google Home – Is It a Spy Device?
Apr 17, 2017, 7:30 AM
Apple added to self –driving test permit list
Apr 15, 2017, 6:21 AM
Project Scorpio – Coming on June 11
Apr 14, 2017, 6:20 AM
Looks Like Samsung Has Been Forgiven.
Apr 13, 2017, 6:50 AM
United Airlines - Blasted on China’s Social Network and the Stock Market
Apr 12, 2017, 6:50 AM
Amazon's Third-Party Sellers Hacked
Apr 11, 2017, 6:25 AM
Microsoft Surface Pro5 Details Revealed
Apr 9, 2017, 6:41 AM
Own An Android Phone? Then you could be hacked over Wi-FI
Apr 7, 2017, 6:47 AM
Apple confirms iOS 10.3 bug and its effect on iCloud Services
Apr 6, 2017, 6:30 AM
Apple Rolls Out New Version of Apple Music
Apr 5, 2017, 10:35 AM
Apple in the News
Apr 4, 2017, 9:03 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information