An attack on MySQL's login protocol

I. Arce, Emiliano Kargieman, Gerardo Richarte, Carlos Sarraute, Ariel Waissbein · arXiv (Cornell University) · 2010

The MySQL challenge-and-response authentication protocol is proved insecure. We show how can an eavesdropper impersonate a valid user after witnessing only a few executions of this protocol. The algorithm of the underlying attack is presented. Finally we comment about implementations and statistical results.

Read the paper · More papers on PaperTik