The 2012 Pwnie Winner For Best Server-Side Bug

“Are we there yet?” MySQL Authentication Bypass (CVE-2012-2122)

Credit: Sergei Golubchik

On vulnerable versions of MySQL simply asking to authenticate repeatedly enough times is enough to bypass authentication: “Can I log in as root now?”
“How about now?”
“Now?”
For actual details, check out Pwnie Judge extraordinaire HD Moore’s blog post.

 (CVE-2012-2122)