3 ms·
Actually, the solution is not to ever use phpMyAdmin on a public web server. Just like Webmin, and every other tool that has god-like power over critical system
by rcoder 18y ago
Actually, the solution is not to ever use phpMyAdmin on a public web server. Just like Webmin, and every other tool that has god-like power over critical system resources, it should be on a private IP, accessible only from trusted systems via an encrypted, strongly-authenticated channel.
- jrockway 18y agoThis doesn't help. If you use the same web browser for using phpMyAdmin that you use for visiting the attacker's site, you're hacked.
- rcoder 18y ago"Strongly-encrypted channel" basically means VPN in my book. If the phpMyAdmin server isn't on a publicly-routable IP, and you don't have the VPN tunnel open when you aren't using the secure host, then it will in fact defeat CSRF.
- simonw 18y agoAgain, CSRF defeats those defences.