Oracle MySQL Server Username Enumeration Weakness Remote Vulnerability
31 Dec. 2012
Summary
Oracle MySQL Server is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Credit:
The information has been provided by Kingcope.
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
Attackers can use readily available tools to exploit this issue.