Index: [Article Count Order] [Thread]

Date:  Fri, 03 Jul 2009 07:49:55 +0100
From:  Linux-Gnome <linux-gnome (at mark) nickcr.co.uk>
Subject:  [coba-e:15781] Re: Restrict phpmyadmin to local machines only
To:  coba-e (at mark) bluequartz.org
Message-Id:  <4A4DAA13.1010306 (at mark) nickcr.co.uk>
In-Reply-To:  <4A205A463E88434C902F1B2007F5FE17@OfficeKen>
References:  <4A48FFE9.5070306 (at mark) nickcr.co.uk> <4A205A463E88434C902F1B2007F5FE17 (at mark) OfficeKen>
X-Mail-Count: 15781

Ken

Changing the alias sounds like a good way to diver people from obvious 
names, could you give me a bit of guidance on how to do this properly.


Regards

    Gnome

Ken Marcus - Precision Web Hosting, Inc. wrote:
> 
> ----- Original Message ----- From: "Linux-Gnome" <linux-gnome (at mark) nickcr.co.uk>
> To: <coba-e (at mark) bluequartz.org>
> Sent: Monday, June 29, 2009 10:54 AM
> Subject: [coba-e:15747] Restrict phpmyadmin to local machines only
> 
> 
>> My server has recently been getting a number of hits of people trying 
>> to hack into phpmyadmin (version v2.7.0-pl1) and as I do not require 
>> any external access to it I wanted to restrict access to all machines 
>> except those on my local network, after a bit of searching I added the 
>> following to "/home/phpmyadmin/config.inc.php"
>>
>> /**
>> * block root from logging in except from the private networks
>> */
>> $cfg['Servers'][$i]['AllowDeny']['order'] = 'deny,allow';
>> $cfg['Servers'][$i]['AllowDeny']['rules'] = array(
>> 'deny from all',
>> 'allow from localhost',
>> 'allow from 192.168.0.0/23',
>> );
>>
>>
>> Unfortunately this did not work (down to my novice knowledge) so I am 
>> after some assistance and guidance on how I should proceed.
>>
>> As an aside, how do I restart phpmyadmin without bouncing the box ?
>>
>> regards
>>
>>   Gnome
> 
> 
> One other option would be to change the alias from /phpmyadmin/
> to something like
> /phpmyadmin2288/
> 
> 
> 
> ----
> Ken Marcus
> Ecommerce Web Hosting by
> Precision Web Hosting, Inc.
> http://www.precisionweb.net
> 
> 
> 
> ------------------------------------------------------------------------
> 
> 
> No virus found in this incoming message.
> Checked by AVG - www.avg.com 
> Version: 8.5.375 / Virus Database: 270.12.94/2208 - Release Date: 06/29/09 05:54:00
>