AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.html?storyid=6619
Published: 2009-06-21 - "…Upon further investigation it appears that her server had been compromised by exploitation of the vulnerability detailed in PMASA-2009-4**. The attacker uploaded a lot of the same old types of tools such as a misnamed EnergyMech IRC bot, a perl based UDP flodding tool, and an automated tool to attempt phpMyAdmin. It is now past time to update to phpMyAdmin 3.1.3.2* (or higher) and/or updating firewall rules to limit the public Internet from touching this web application…
06/22/2009 22:30 UTC - …more reports locally about activity which seems to point to phpMyAdmin scanning and exploitation…"
* http://www.phpmyadmin.net/home_page/index.php
phpMyAdmin 3.2.0
File Release Notes and Changelog
- http://sourceforge.net/project/shownotes.p…lease_id=690019
Last Update: Jun 15 2009
** http://www.phpmyadmin.net/home_page/securi…MASA-2009-4.php

- http://isc.sans.org/diary.html?storyid=6619
Published: 2009-06-21 - "…Upon further investigation it appears that her server had been compromised by exploitation of the vulnerability detailed in PMASA-2009-4**. The attacker uploaded a lot of the same old types of tools such as a misnamed EnergyMech IRC bot, a perl based UDP flodding tool, and an automated tool to attempt phpMyAdmin. It is now past time to update to phpMyAdmin 3.1.3.2* (or higher) and/or updating firewall rules to limit the public Internet from touching this web application…
06/22/2009 22:30 UTC - …more reports locally about activity which seems to point to phpMyAdmin scanning and exploitation…"
* http://www.phpmyadmin.net/home_page/index.php
phpMyAdmin 3.2.0
File Release Notes and Changelog
- http://sourceforge.net/project/shownotes.p…lease_id=690019
Last Update: Jun 15 2009
** http://www.phpmyadmin.net/home_page/securi…MASA-2009-4.php