If one tries to connect with an incorrect password, the connection is aborted, one has to connect again to try a new password. But if one tries an incorrect password with the COM_CHANGE_USER command, he is not disconnected, which allows to brute-force passwords faster. Additionally, all COM_CHANGE_USER issued in a connection use the same scramble value.
We can fix it by allowing only three (or any other small fixed number?) of failed COM_CHANGE_USER in a connection.
It probably shouldn't be "three fails in a row", because one would be able to alternate between two known accounts and continue trying other password.
Additionally we might add a one second (or any other short fixed time duration) delay after a failed connection or a COM_CHANGE_USER attempt.
Sergei Golubchik
made changes -
2013-01-24 14:40
Field
Original Value
New Value
Status
Open
[ 1
]
In Progress
[ 3
]
Sergei Golubchik
made changes -
2013-01-24 23:37
Fix Version/s
5.1.67
[ 12100
]
Fix Version/s
5.2.14
[ 12101
]
Fix Version/s
5.3.12
[ 12000
]
Sergei Golubchik
made changes -
2013-01-24 23:39
Fix Version/s
5.3.12
[ 12000
]
Fix Version/s
5.2.14
[ 12101
]
Fix Version/s
5.1.67
[ 12100
]
Sergei Golubchik
made changes -
2013-01-25 12:48
Resolution
Fixed
[ 1
]
Status
In Progress
[ 3
]
Closed
[ 6
]
Sergei Golubchik
made changes -
2014-06-13 15:06
Workflow
defaullt
[ 25504
]
MariaDB v2
[ 45690
]
Sergei Golubchik
made changes -
2021-12-06 21:38
Workflow
MariaDB v3
[ 66385
]
MariaDB v4
[ 146248
]
{"report":{"fcp":1628.2999992370605,"ttfb":840.5999994277954,"pageVisibility":"visible","entityId":22204,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"27d85b88-5602-4a52-95b7-657a75284d0f","navigationType":0,"readyForUser":1698.0999994277954,"redirectCount":0,"resourceLoadedEnd":1877.1999998092651,"resourceLoadedStart":846.1999998092651,"resourceTiming":[{"duration":248.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":846.1999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":846.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1094.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":248.69999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":846.3999996185303,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":846.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1095.0999994277954,"responseStart":0,"secureConnectionStart":0},{"duration":301.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/e9b27a47da5fb0f74a35acd57e9847fb-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":846.6999998092651,"connectEnd":846.6999998092651,"connectStart":846.6999998092651,"domainLookupEnd":846.6999998092651,"domainLookupStart":846.6999998092651,"fetchStart":846.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":846.6999998092651,"responseEnd":1148.1999998092651,"responseStart":1148.1999998092651,"secureConnectionStart":846.6999998092651},{"duration":386.6000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/s/c32eb0da7ad9831253f8397e6cc26afd-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":846.7999992370605,"connectEnd":846.7999992370605,"connectStart":846.7999992370605,"domainLookupEnd":846.7999992370605,"domainLookupStart":846.7999992370605,"fetchStart":846.7999992370605,"redirectEnd":0,"redirectStart":0,"requestStart":846.7999992370605,"responseEnd":1233.3999996185303,"responseStart":1233.3999996185303,"secureConnectionStart":846.7999992370605},{"duration":390.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/bc0bcb146314416123c992714ee00ff7-CDN/lu2bv2/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":847.0999994277954,"connectEnd":847.0999994277954,"connectStart":847.0999994277954,"domainLookupEnd":847.0999994277954,"domainLookupStart":847.0999994277954,"fetchStart":847.0999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":847.0999994277954,"responseEnd":1237.2999992370605,"responseStart":1237.1999998092651,"secureConnectionStart":847.0999994277954},{"duration":390.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":847.1999998092651,"connectEnd":847.1999998092651,"connectStart":847.1999998092651,"domainLookupEnd":847.1999998092651,"domainLookupStart":847.1999998092651,"fetchStart":847.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":847.1999998092651,"responseEnd":1237.6999998092651,"responseStart":1237.6999998092651,"secureConnectionStart":847.1999998092651},{"duration":390.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":847.5,"connectEnd":847.5,"connectStart":847.5,"domainLookupEnd":847.5,"domainLookupStart":847.5,"fetchStart":847.5,"redirectEnd":0,"redirectStart":0,"requestStart":847.5,"responseEnd":1238,"responseStart":1238,"secureConnectionStart":847.5},{"duration":444.6000003814697,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bv2/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":847.5999994277954,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":847.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1292.1999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":390.6000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":847.7999992370605,"connectEnd":847.7999992370605,"connectStart":847.7999992370605,"domainLookupEnd":847.7999992370605,"domainLookupStart":847.7999992370605,"fetchStart":847.7999992370605,"redirectEnd":0,"redirectStart":0,"requestStart":847.7999992370605,"responseEnd":1238.3999996185303,"responseStart":1238.3999996185303,"secureConnectionStart":847.7999992370605},{"duration":444.29999923706055,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":848,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":848,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1292.2999992370605,"responseStart":0,"secureConnectionStart":0},{"duration":390.9000005722046,"initiatorType":"script","name":"https://jira.mariadb.org/s/719848dd97ebe0663199f49a3936487a-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":848.0999994277954,"connectEnd":848.0999994277954,"connectStart":848.0999994277954,"domainLookupEnd":848.0999994277954,"domainLookupStart":848.0999994277954,"fetchStart":848.0999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":848.0999994277954,"responseEnd":1239,"responseStart":1239,"secureConnectionStart":848.0999994277954},{"duration":559.3999996185303,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":848.8999996185303,"connectEnd":848.8999996185303,"connectStart":848.8999996185303,"domainLookupEnd":848.8999996185303,"domainLookupStart":848.8999996185303,"fetchStart":848.8999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":848.8999996185303,"responseEnd":1408.2999992370605,"responseStart":1408.2999992370605,"secureConnectionStart":848.8999996185303},{"duration":1024.1000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":853.0999994277954,"connectEnd":853.0999994277954,"connectStart":853.0999994277954,"domainLookupEnd":853.0999994277954,"domainLookupStart":853.0999994277954,"fetchStart":853.0999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":853.0999994277954,"responseEnd":1877.1999998092651,"responseStart":1877.1999998092651,"secureConnectionStart":853.0999994277954},{"duration":107.90000057220459,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1303.7999992370605,"connectEnd":1303.7999992370605,"connectStart":1303.7999992370605,"domainLookupEnd":1303.7999992370605,"domainLookupStart":1303.7999992370605,"fetchStart":1303.7999992370605,"redirectEnd":0,"redirectStart":0,"requestStart":1303.7999992370605,"responseEnd":1411.6999998092651,"responseStart":1411.6999998092651,"secureConnectionStart":1303.7999992370605},{"duration":381.19999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bv2/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1566,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1566,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1947.1999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":365.6000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1566.8999996185303,"connectEnd":1566.8999996185303,"connectStart":1566.8999996185303,"domainLookupEnd":1566.8999996185303,"domainLookupStart":1566.8999996185303,"fetchStart":1566.8999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":1566.8999996185303,"responseEnd":1932.5,"responseStart":1932.5,"secureConnectionStart":1566.8999996185303},{"duration":370.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/53a43b6764f587426c7bb9a150184c00-CDN/lu2bv2/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":1567.1999998092651,"connectEnd":1567.1999998092651,"connectStart":1567.1999998092651,"domainLookupEnd":1567.1999998092651,"domainLookupStart":1567.1999998092651,"fetchStart":1567.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":1567.1999998092651,"responseEnd":1937.3999996185303,"responseStart":1937.3999996185303,"secureConnectionStart":1567.1999998092651}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":642,"responseStart":840,"responseEnd":845,"domLoading":844,"domInteractive":1903,"domContentLoadedEventStart":1903,"domContentLoadedEventEnd":1947,"domComplete":2364,"loadEventStart":2364,"loadEventEnd":2365,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1879},{"name":"bigPipe.sidebar-id.end","time":1879.8999996185303},{"name":"bigPipe.activity-panel-pipe-id.start","time":1880.0999994277954},{"name":"bigPipe.activity-panel-pipe-id.end","time":1883},{"name":"activityTabFullyLoaded","time":1963.7999992370605}],"measures":[],"correlationId":"288d6285f4fbe","effectiveType":"4g","downlink":9.7,"rtt":0,"serverDuration":118,"dbReadsTimeInMs":21,"dbConnsTimeInMs":30,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
http://seclists.org/fulldisclosure/2012/Dec/58