Monday, September 21, 2009

phpmyadmin attack

another reason why you should not extract files that retain the default structure. here's a list of addresses for phpmyadmin someone tried to access unsuccessfully

/mysqladmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin2//setup/config.php?type=post HTTP/1.1
/phpmyadmin2//setup/config.php?type=post HTTP/1.1
/myadmin//setup/config.php?type=post HTTP/1.1
/MyAdmin//setup/config.php?type=post HTTP/1.1
/myAdmin//setup/config.php?type=post HTTP/1.1
/phpAdmin//setup/config.php?type=post HTTP/1.1
/phpadmin//setup/config.php?type=post HTTP/1.1
/mysql//setup/config.php?type=post HTTP/1.1
/pma//setup/config.php?type=post HTTP/1.1
/phpmyadmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin//setup/config.php?type=post HTTP/1.1

I particularly like this agent used:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]

Thanks for the visit. 217.145.96.131

No comments:

Post a Comment