11 ms·
PhpMyAdmin Project Successfully Completes Security Audit
- smaili 10y agoDoes anyone still use this? I didn't realize this was still actively maintained.
- donjh 10y agoCountless people maintaining WordPress sites do.
- drzaiusapelord 10y agoEvery Drupal dev shop we've worked this insisted this was installed on the server. Its just firewalled off/tunneled/whatever for safety.
- creshal 10y agoIf you are using MySQL, and need to manually fuck around with tables for whatever reason, it's really useful and beats most other options. For us it sees plenty of use with poorly developed legacy software (e.g. Wordpress).
- martinczerwi 10y agoYou might like this: https://www.dbninja.com/ https://www.dbninja.com/
- pinum 10y agoI can't think of much reason to use it over Workbench or Sequel Pro.
- bowlich 10y agoSequel Pro - No native linux support Workbench - Massively unstable on linux. (Although I do like the visualizing tools assuming I'm willing to put up with it crashing every hour or so).
- whatsamattayou 10y agoSome dev environments aren't local, and sometimes this is faster, especially if you have to document the changes for future updates that don't include your fancy tools.
- creshal 10y agoOh, if only were we using it only in dev environments…
- markplindsay 10y agoSequel Pro's built-in SSH tunnel has worked for me in every remote development situation I've encountered. It seems like a really bad idea to place a web-based database tool on a public-facing host when technology exists to route MySQL through SSH. Even shared hosts support SSH these days. If yours doesn't, maybe it's time to find another shared host!
- smhenderson 10y agoIt's been a while but I'm pretty sure you can do so with PHPMyAdmin. I seem to remember installing it on my own workstation, setting up the ssh tunnel and then pointing PHPMA to localhost. It's not my favorite tool and I've avoided it due to security concerns but I've set it up for others as described and I recall it worked fine. Like I said though it's been a while and I'm fuzzy on the details.
- knowaveragejoe 10y agoWorkbench has some great features that I can't do without, but when it comes to just browsing around a DB I much prefer PhpMyAdmin's interface over it. That said I haven't really tried any of the other offerings in the space, so I expect that's a big part of my opinion.
- exclusiv 10y agoI agree with this comparison but Navicat is well worth the price. I use their data backup and synchronization (data and/or structure) all the time and it works extremely well. The "find in database" text search is a life saver too.
- onion2k 10y agoIf you need to make a manual database change then Adminer is often a better option[1]. It's doesn't have the featureset as PHPMyAdmin but it has a huge advantage in that it's a single PHP file you can upload, make the necessary changes, and then delete. If you're interested in maintaining a secure server but you don't have any better options than using a script, then it's better to upload something when you need it than trying to secure an online admin tool. [1] https://www.adminer.org/ https://www.adminer.org/
- creshal 10y ago> It's doesn't have the featureset as PHPMyAdmin but it has a huge advantage in that it's a single PHP file you can upload, make the necessary changes, and then delete The days of painfully slow FTP servers are long gone where "it's one file" would count as advantage. This leaves a massively worse UX and featureset. (We are using adminer for postgresql databases, because there's no better alternative, and it makes me wish phpmyadmin supported postgres every time I have to use it.)
- onion2k 10y agoHaving a single file isn't an advantage from a speed perspective; the advantage lies in only having to upload a file, make a change and delete the file again. There's no install, no config, etc.
- deleted 10y ago[deleted]
- ivanceras 10y agoDidn't postgresql community just annouced pgadmin4 lately and it seems to come with a modern webclient https://www.pgadmin.org/ https://www.pgadmin.org/
- ZenoArrow 10y agoDo any of these web-based DB tools come with autocomplete? I'd say that's the feature I value most when using desktop DB tools.
- overcast 10y agoMySQL Workbench works fine though?
- LeonM 10y ago+1 for this. The profiler (visual explain) of queries in MySQL workbench is a godsend. Also, for general querying and table layout lookup in OSX (macOS, whatever) I recommend Sequel Pro. It has a slightly better UI when working with multiple databases (easier to switch).
- bowlich 10y agoLast time I tried it (about two years ago). It would crash all the time on Ubuntu. Went back to PHPMyAdmin.
- overcast 10y agoMine kept crashing on Mac when viewing table information, turns out it was some old subversion plugin that integrated into the OS shell.
- waterphone 10y agoAnyone using shared hosting (e.g. most people who do web development for small businesses) does.
- toxican 10y agoI think many (most?) web developers get their start on some shared hosting provider where your only obvious option for managing MySQL databases is phpmyadmin. You have to dig a little deeper to realize you cna use MySQL Workbench, but even then a lot of them disable remote MySQL and SSH so you're SOL. So for me, at least, it's ingrained in my head that phpmyadmin is the best tool for the job given the limitations of what I've got. Although I recently switched my company's reseller hosting account to a provider that actually allows remote MySQL or SSH, so that's exciting.
- 20years 10y agoI personally use Workbench when I can but a lot of clients with shared hosting use it. It still gets the job done for the most part.
- blowski 10y agoIt usually comes by default with CPanel and Plesk on web servers, as well as MAMP / WAMP / XAMPP for development environments. In my experience it's still used a lot by junior devs who haven't yet learned any different, and people with absolutely no idea what they're doing.
- 23andwalnut 10y agoWhat are some good alternatives? I've been using DataGrip the last couple of months, but prior to that I used phpMyAdmin all the time because I just couldn't find anything else as useful for MySQL. And even with DataGrip, I sometimes have to log in to phpmyadmin because there's stuff DataGrip doesn't do....
- acomjean 10y agoYes. A lot of times its available on shared hosting behind some login. Esp, if you don't have shell access on inexpensive hosts. Its been available at places I've worked. It was locked down by IP. The database was restricted to access by ip too, in theory making outside access more difficult. I used it a lot (less now) and honestly, I kind of like it. The interface is a little kludgy, but it gets the job done. Queries are editable, exportable in various formats. You can construct a search via gui then edit the SQL it generates . It seems to have a lot of functionality built in, user/table management etc.. For local instances I use sequel pro too (the ssh login function it has is nice and works well).
- hackaflocka 10y agoPHPMyAdmin is a lifesaver for newbies and those who are intimidated by the Command Line. It was for me, and I still prefer to use it when possible. I can't thank the people who created it and maintain it enough.
- callesgg 10y agoI think it is one of the best mariadb/mysql gui's out there. But to get the good stuff one has to configure it properly, and generally people don't bather configuring it. They just place the files in a folder. No other web based tool for any database that i have tried even comes close.
- sync 10y ago> A lack of filtering on user CSV output that could allow an attacker to run arbitrary code on an administrator's computer. > Improper cookie invalidation that could allow an attacker to unset internal global variables. Those don't count as serious issues? Props to them for making the report public though.
- creshal 10y ago> > A lack of filtering on user CSV output that could allow an attacker to run arbitrary code on an administrator's computer. Iff the user has Excel, and explicitly allows it to run macros in a CSV file. It's already a stretch to call this a phpMyAdmin vulnerability, much less a "medium severity" one. > > Improper cookie invalidation that could allow an attacker to unset internal global variables. From the PDF report: > Note: Because of the large amount of global variables, and the relatively short nature of this assessment, NCC Group was unable to fully determine the impact of this vulnerability. It might be serious, but they didn't have enough budget to make a proper analysis.
- Rangi42 10y ago> Because of the large amount of global variables... NCC Group was unable to fully determine the impact of this vulnerability. In other words, "This project is too full of potential security holes to find the definite ones."
- drzaiusapelord 10y agoNo, it means we understand there are theoretical security issues with global variables, but cannot determine if they're actually applicable or exploitable in this software.
- MustardTiger 10y agoYou just repeated exactly the same thing he said as if you were disagreeing.
- igravious 10y agoSecure Open Source has completed[1] the following audits. - PCRE v2 audited by Cure53[2] 1 Critical 5 Medium 20 Low 3 Informational - libjpeg-turbo audited by Cure53 1 High 2 Medium 2 Low - phpMyAdmin audited by NCC Group[3] 3 Medium 5 Low 1 Informational [1] https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed [2] https://cure53.de/ https://cure53.de/ [3] https://www.nccgroup.trust/uk/ https://www.nccgroup.trust/uk/
- creshal 10y agoAnd in the PDF, the auditors complain that they didn't have enough time to even fully analyze the impact of the vulnerabilities found. I wouldn't read too much into it.
- Johnny_Brahms 10y agoThat is misleading. They said they had the ability to unset global variables. Looking at the PHPMyAdmin codebase, I understand they didn't have the time.
- Ded7xSEoPKYNsDd 10y agoIf fixing the bug is less work then determining exploitability, fixing it and moving on is just economical. Digging in further would only have distracted from looking for other vulnerabilities.
- baby 10y agoThis is not relevant. An audit cost a substantial amount of money, you wouldn't expect your consultants to spend a lot of time exploiting or building Proof-of-Concepts. If you have a time-boxed assessments, you want the consultants to cover the most ground and not spend too much time on a finding.
- fauria 10y agoDoes anyone know how much (approximately) this audit could have costed?
- dsacco 10y agoGiven that the assessment occupied two weeks with two consultants, between $25,000 - $35,000. I don't have intimate knowledge of NCC Group's pricing structure because I don't work there. But I have friends who do, and similarly situated consultancies that I've worked for are in the $10,000/week range for a one-off assessment with non-senior staff. This is also somewhat close to what I charge through my own smaller consulting practice. Now, if there was specialty work (like crypto), particularly comprehensive work, more consultants billed on the assessment than usual or senior/principal consultants billed on the assessment, the total fee would go up. This is why I added a $10,000 premium to my estimate; the source code analysis detailed in this report might qualify as "non-standard." That said, NCC might have worked on a discount for the opportunity to advertise that they were involved in the audit. But I don't see this assessment having costed anything less than $20,000 even in a charitable situation.
- zhte415 10y ago$10,000/week range seems low for a week long audit, but depends on time charged. Most audits I've worked on, while a week long, have a 2 week pre-audit familiarization period for the audit team, and a 1 week long post-audit report-writing period. This means a 1 week audit is an actual week of investigation, and for $10,000 this sounds low. Via the article, it seems like a leading client / lead of future potential client, so discount works on many levels. And from TFA: Conservancy and the phpMyAdmin project are proud of the results and thank Mozilla for funding and initiating the audit.
- dsacco 10y agoInteresting. Do you mind if I ask what sort of audits you were working on? I can understand the 2 week pre-audit familiarization period. How would you price this out instead? I was operating under the assumption that the pre-audit familiarization was priced into the first week as threat modeling and discovery. This would also lend credence to the report admitting that they did not have time to investigate as thoroughly as they would have liked. I did forget to include the post-audit report-writing period, it's been a while since that was a thing for me. I've never billed for that in my own practice because I disagree with the idea of billing for five days of work that essentially boils down to "fill in findings and application details into a long-form, templated PDF." I've also never seen a consultant really need five days to complete one of those :). I'm sure folks like Tom will come in shortly to beat me over the head for not charging for this part of the assessment. I don't understand what you mean by this though: > And from TFA: Conservancy and the phpMyAdmin project are proud of the results and thank Mozilla for funding and initiating the audit. I do agree it's likely that there is a discount here for future or publicly recognizable work.
- CiPHPerCoder 10y agoI wish NCC Group had been given more time, since phpMyAdmin is nigh-ubiquitous in legacy PHP apps. For example: https://github.com/phpmyadmin/phpmyadmin/blob/4cd8ab8a957a2324b4e218acc048642b9a6d2a23/libraries/session.inc.php https://github.com/phpmyadmin/phpmyadmin/blob/4cd8ab8a957a23... Despite setting several security-related session configuration values, they don't touch the cookie entropy fields, which means a potential session fixation vulnerability. This might not be a concern for most users: typically your distro ships a php.ini configured to read at least 16 bytes from /dev/urandom. But not always! Many projects set cookie.entropy_length and cookie.entropy_source just to be sure.
- arrmn 10y agoStupid question, how does a security audit work? Do the consultants just read through the code? Do they try to find security bug like they do on bug bounty programs?
- sb8244 10y agoI'm not an expert in this field, but we recently did a security audit. The auditors get access to the code in order to evaluate it for vulnerabilities. In our ruby application, they also check gems that we are using (through open source tools albeit). They also did an in-app audit where they tried to break the application however they might see that. Having access to the code helps with this. When you get audited by potential customer, it usually involves not having code access and trying to penetrate the app without that access.
- BinaryIdiot 10y ago> When you get audited by potential customer, it usually involves not having code access and trying to penetrate the app without that access. Is this in reference to on-prem / enterprise software and is this typical? I haven't heard of customers doing this but it certainly makes sense (might as well invest thousands to test before spending magnitudes more on the product itself only to find it having a huge security hole). Then again I'm not sure I've worked with potential customers who have access to do something like that.
- softawre 10y agoWe just signed a big deal with a Google subsidiary, and part of that deal required us to go through a third party penetration test (no code access).
- BinaryIdiot 10y agoWell today I learned. Thanks!
- dsacco 10y ago
- fideloper 10y agoI really hate the idea of having a web interface to my database anywhere, no matter how secure they say it is. Social engineering (over direct "hacking") lends itself to circumventing technical security. No matter their technical security (Although I'm super happy they test phpmyadmin!), I still wouldn't trust it on my servers. Granted you can lock phpmyadmin down via ip restriction, vpn, etc - that's definitely good, but, if you can forgive a bit of generalization, those measure tend to be above people's head or too restrictive for those using phpmyadmin. If we do connect to a database using a GUI (usually an app instead of phpmyadmin), however, my preference is through an SSH tunnel. This lets us connect securely (over SSH), and still allow MySQL to not be globally accessible from the outside world - meaning, you can still using MySQL's built-in network security features (bind-address and username hosts, along with firewall restrictions) to lock down MySQL.
- labster 10y ago> I really hate the idea of having a web interface to my database anywhere, Aren't those called "applications"? And yes, I hate them too.
- ivanhoe 10y agoWhy do you presume that web app has to be run public? You can easily limit access to web app by IP, or you can put it on a private network that you will access through VPN. That would make it more secure than most web services that we trust regularly, like gmail or paypal...
- CiPHPerCoder 10y agoIf you're going to do this, go the VPN route.
- dvt 10y agoFor a prospective hacker, I don't think there's much of a (functional) difference between a graphical interface or a shell.
- 10y ago
- Xeoncross 10y agoI encourage people to google how to run phpMyAdmin, MySQL Workbench, or Sequel Pro locally, and use port forwarding over SSH. It's super simple. Here is a command that forwards all traffic to localhost:3306 across the ssh tunnel to example.com:3306 (the mysql default port). ssh user@example.com -L 3306:localhost:3306 I would never run a DB admin application on the live server because it's just one more piece that might open a security hole.
- xrstf 10y agoOn Windows, I recommend using HeidiSQL, which handles SSH tunnels for you using PuTTY's plink.exe.
- jredwards 10y agoI like some of the HeidiSQL tools so much that I run it via WINE on my mac.
- voycey 10y agoBe wary of Heidi and SSH tunnelling on windows - I'm sure the bugs have been fixed but I first hand realised that it re-used the tunnel for subsequent connections meaning you were not making changes on the database you thought you were - definitely caused some problems! However it is such a good client that I now use it on Linux under Wine :)
- voycey 10y agohttps://sourceforge.net/p/heidisql/tickets/2832/ https://sourceforge.net/p/heidisql/tickets/2832/ Found my original ticket! And yes, I truncated a few production tables :(
- kgdinesh 10y agoApart from security, are there any other benefits?
- bdcravens 10y ago
- EGreg 10y agoHow can we get such audits done for our own open source projects?
- oxguy3 10y agoThere are selection criteria listed at https://wiki.mozilla.org/MOSS/Secure_Open_Source https://wiki.mozilla.org/MOSS/Secure_Open_Source , and, if you think you meet most of the criteria, you can fill out a form to apply.
- shaunrussell 10y ago10 years late.
- oaf357 10y agoI encourage everyone to use MySQL Workbench over SSH. For whatever reason people seem to not understand the concept of SSH and the inherent security it provides. But, once you explain to folks how to use it effectively it really is a good balance of security and usability.
- homakov 10y agoIs there much sense in auditing things that are usually used by the admin and are by design exposing a lot of control of the server? Sure it must not be exposed to an outsider, but if auth is done right, it doesn't matter how far the insider can get... IMO
- sixhobbits 10y ago"I'm not sure, what the guys did during the audit of phpMyAdmin, but it took me 3 minutes to find a persistent XSS in the latest version." https://twitter.com/totally_unknown/status/742753323468640262 https://twitter.com/totally_unknown/status/74275332346864026...
- scottydelta 10y ago> Software Freedom Conservancy congratulates its phpMyAdmin project on succesfuly completing completing a thorough repetition of "completing" in first line.