Re: phpmyadmin auth

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 7/9/2013 5:46 PM, Jim Albert wrote:
On 7/9/2013 5:21 PM, Jerry K wrote:
configure a local VPN, and only allow access from the VPN IP range is
one possible "Plan B".

Reviewing my own log files, its amazing how many malware hits there are
for this particular software product.

What ever you do, be as safe/secure as you can.

Good Luck

Jerry
Agreed; the default phpmyadmin aliases are a very common attack point.
VPN/private address space would absolutely be the best solution, but if
that's not possible then on top of htpasswd authentication with strong
passwords, some "security through obscurity" in changing the alias is
probably not a bad idea to keep out the bot attacks.

Jim
... and verify that SSLRequireSSL is enforced and it should be if you are using the phpmyadmin.conf config file.

Jim


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx





[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux