This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

phpMyAdmin scans...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=6619
Published: 2009-06-21 - "…Upon further investigation it appears that her server had been compromised by exploitation of the vulnerability detailed in PMASA-2009-4**. The attacker uploaded a lot of the same old types of tools such as a misnamed EnergyMech IRC bot, a perl based UDP flodding tool, and an automated tool to attempt phpMyAdmin. It is now past time to update to phpMyAdmin 3.1.3.2* (or higher) and/or updating firewall rules to limit the public Internet from touching this web application…
06/22/2009 22:30 UTC - …more reports locally about activity which seems to point to phpMyAdmin scanning and exploitation…"

* http://www.phpmyadmin.net/home_page/index.php
phpMyAdmin 3.2.0
File Release Notes and Changelog
- http://sourceforge.net/project/shownotes.p…lease_id=690019
Last Update: Jun 15 2009

** http://www.phpmyadmin.net/home_page/securi…MASA-2009-4.php

:ph34r:
FYI…

Exploit tools publicly available for phpMyAdmin…
- http://isc.sans.org/diary.html?storyid=6634
Last Updated: 2009-06-24 16:42:44 UTC - "… there (are) at least 2 exploits posted in the last 20 days on public forums for exploiting the bug from March 2009 described here: http://www.phpmyadmin.net/home_page/securi…MASA-2009-3.php *. Suggested advice is to re-verify that your phpMyAdmin is patched and also not accessible to the general Internet to prevent future exploitation of unknown bugs…"
* 2009-03-24 - "… consider this vulnerability to be critical.
Affected Versions:
For 2.11.x: versions before 2.11.9.5.
For 3.x: versions before 3.1.3.1…"

:ph34r: