An attack on MySQL's login protocol
classification
💻 cs.CR
keywords
protocolattackmysqlalgorithmauthenticationchallenge-and-responsecommenteavesdropper
read the original abstract
The MySQL challenge-and-response authentication protocol is proved insecure. We show how can an eavesdropper impersonate a valid user after witnessing only a few executions of this protocol. The algorithm of the underlying attack is presented. Finally we comment about implementations and statistical results.
This paper has not been read by Pith yet.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.