Skip to content

Comment on Root access to MySQL.com sold for $3k - now serving malware

Comments

I've never seen a $$ number associated with these things, but really? Only $3K?

Apparently, I would have overbid if I were in the market for such things.

Well, it may be that the frightening reality is such that supply is so abundant that a single site with 12m dailies doesn't demand the prices one might expect.

edit: 12m monthlies, sorry.

Mysql.com has nowhere near 12m daily uniques.

Right you are, thanks.

its hard to say, but generally the public postings like that are a cover up to cover tracks.

you might imagine that no one ever puts such offer on public (or private with everyone having access to it) kind of boards.

its a very usual thing to do, at least, back in the day <strikeout>we</strikeout> they were doing that every time we weren't 200% sure of our tracks or for highly advertised targets (yeah you risk less hacking a whole ISP than you do hacking a nooby site such as mysql.com)

It wasn't sold for $3K, as far as I can tell. The screenshot linked to reads "Don't bother calling if you don't have $3K". Now that might mean asking price or it might mean an order of magnitude, but it certainly seems like the domain was positioned as on auction.

You also have to figure it's very temporary root access, until a real root user repairs it from an uncompromised offline backup. It's not like they're selling the entire MySQL site in perpetuity for $3k.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.