Nice Try, but The Bad Guys Lose

For a few days, two files on a Sourceforge mirror were modified to ship malware with phpMyAdmin. 400 downloads went out before Sourceforge shut down the mirror. Instead of taking over the world, the bad guys were stopped cold. Globally, Sourceforge counted 50K downloads of phpMyAdmin this week. This is another good reason to check your checksums and scan for malware before using any file from the web. Further, I don’t recommend using phpMyAdmin from the web. One should at least add a couple more layers of security to it like blocking any connection to/from it not from the database-admin’s workstation or using SSH to port the database to the database-admin’s workstation and only using a local copy of phpMyAdmin there.

Using phpMyAdmin from a reputable distro is another layer of security not to be overlooked. I recommend Debian GNU/Linux. Their package manager does verify packages.

see phpMyAdmin distributed with backdoor – The H Open: News and Features.

- Robert Pogson

1 Response to “Nice Try, but The Bad Guys Lose”


  1. 1 oiaohm Sep 26th, 2012 at 4:24 pm

    So much for the claim attackers don’t try to hit open source.

    This kind of attack is not a one off. Lot of monitoring goes on so this stuff gets picked up.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>




Archives by Month

My Mission

My observations and opinions about IT are based on 40 years of use in science and technology and lately, in education. I like IT that is fast, cost-effective and reliable. I do not care whether my solution is the same as yours. I like to think for myself.

My first use of GNU/Linux in 2001 was so remarkably better than what I had been using, I feel it is important work to share GNU/Linux with the world. I have been blessed by working in schools where students and school systems have benefited by good, modular software easily installed in most systems.

I have shown GNU/Linux to thousands of students and hundreds of teachers over the years and will continue in some way doing that until I die in spite of the opposition.

Posts

September 2012
S M T W T F S
« Aug   Oct »
 1
2345678
9101112131415
16171819202122
23242526272829
30  

    Writing

    3428 articles
    30564 comments

      Comments

      platforms
      linux 17444
      windows 12759
      macos 206
      sun 3
      wp 2

      browsers
      firefox 23886 
      safari 11848 
      chrome 11700 
      ie 4633 
      iceweasel 4257 
      opera 1641 
      konqueror 198 
      netnewswire 14 
      epiphany 2 
      flock 0 
      bonecho 0 
      lynx 0 

Bad Behavior has blocked 5104 access attempts in the last 7 days.