arXiv · 1006.2411
An attack on MySQL's login protocol
Abstract
The MySQL challenge-and-response authentication protocol is proved insecure. We show how can an eavesdropper impersonate a valid user after witnessing only a few executions of this protocol. The algorithm of the underlying attack is presented. Finally we comment about implementations and statistical results.
Explore related subjects
Keep this discovery
Ivan Arce, Emiliano Kargieman, Gerardo Richarte, Carlos Sarraute, Ariel Waissbein. 2010-06-11. An attack on MySQL's login protocol. https://arxiv.org/abs/1006.2411
Cite the original work for its findings. Save a collection to share your selection of sources.