3 ms·
What about phpMyAdmin and others alike webapps? Are they inherently insecure?
by vz0 12y ago
What about phpMyAdmin and others alike webapps? Are they inherently insecure?
- deleted 12y ago[deleted]
- coldtea 12y agoThose are different, as they only do what they are meant to do (give access to the databases). They don't give untintended full access to the web server. That said, they are a little insecure.
- blueskin_ 12y ago>They don't give unintended full access to the web server. https://en.wikipedia.org/wiki/Webmin https://en.wikipedia.org/wiki/Webmin Maybe not unintended, but definitely full access, and the world is almost certainly full of outdated/non whitelist access/weakly passworded panels. Also, on a a sufficiently misconfigured server, you could always use \! (mysql's shell_exec, etc.) with phpmyadmin etc. to open a remote shell somewhere, then work from there.
- deleted 12y ago[deleted]