Crit.org - http://www.crit.org
Possible New Worm Hits Windows Machines Running MySQL
http://www.crit.org/articles/4/1/Possible-New-Worm-Hits-Windows-Machines-Running-MySQL
Crit [dot] Org
 
By Crit [dot] Org
Published on 01/28/2005
 

Following a report on the Australian whirlpool forums, there is a new possible worm in the wild. Similar to ‘Slammer’ and ‘SQLSnake’ in that it targets vulnerable MySQL servers, there is potential for this new worm to wreak havoc.

 

 SANS Internet Storm Center is suggesting that a rise in port 3306 scans could be a result of this new worm. Apparently the worm creates a file called ‘spoolcll.exe’.

 

Recommendation:

Until this worm has been identified and a hotfix or solution provided, it is recommended that Admin’s of Windows MySQL systems keep a close eye on their boxes and the above file appearing on their machines.


http://forums.whirlpool.net.au/forum-replies.cfm?t=291921