<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protect your phpMyAdmin folder, or &#8230;</title>
	<atom:link href="http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html/feed" rel="self" type="application/rss+xml" />
	<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html</link>
	<description>WordPress, JavaScript, Android and some random stuff</description>
	<lastBuildDate>Fri, 30 Jul 2010 13:51:32 +0530</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: infySEC Staff</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-585975</link>
		<dc:creator>infySEC Staff</dc:creator>
		<pubDate>Wed, 26 May 2010 22:42:48 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-585975</guid>
		<description>Hi Mayur. Check out our new upcoming hackEDGE 2010 - 2 Days Ethical Hacking Hands-On Practical Workshop program in Chennai, TamilNadu.
http://www.infysec.com/events/hackedge/

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi Mayur. Check out our new upcoming hackEDGE 2010 &#8211; 2 Days Ethical Hacking Hands-On Practical Workshop program in Chennai, TamilNadu.<br />
<a href="http://www.infysec.com/events/hackedge/" rel="nofollow">http://www.infysec.com/events/hackedge/</a></p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mayur</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-585405</link>
		<dc:creator>Mayur</dc:creator>
		<pubDate>Fri, 21 May 2010 08:13:04 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-585405</guid>
		<description>This is very interesting, i never knew there are such practical events based on hacking, it must be great. Hacking seem to be a good field.</description>
		<content:encoded><![CDATA[<p>This is very interesting, i never knew there are such practical events based on hacking, it must be great. Hacking seem to be a good field.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sudar</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-545040</link>
		<dc:creator>Sudar</dc:creator>
		<pubDate>Thu, 13 Aug 2009 03:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-545040</guid>
		<description>@Vino,

Sure :)

Send you an email with my details.</description>
		<content:encoded><![CDATA[<p>@Vino,</p>
<p>Sure <img src='http://sudarmuthu.com/wpfiles/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Send you an email with my details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sudar</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-545039</link>
		<dc:creator>Sudar</dc:creator>
		<pubDate>Thu, 13 Aug 2009 03:52:35 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-545039</guid>
		<description>@InfySEC Staff,

Thanks for the event. Yes the *lesson* learned was priceless :)

Will send a mail to you guys with my feedback. BTW is it possible to get copies of the presentation which were made during the event?</description>
		<content:encoded><![CDATA[<p>@InfySEC Staff,</p>
<p>Thanks for the event. Yes the *lesson* learned was priceless <img src='http://sudarmuthu.com/wpfiles/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Will send a mail to you guys with my feedback. BTW is it possible to get copies of the presentation which were made during the event?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vino</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544899</link>
		<dc:creator>Vino</dc:creator>
		<pubDate>Wed, 12 Aug 2009 22:27:01 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544899</guid>
		<description>can i hv ur chat id sudarmuthu.thanks
vino</description>
		<content:encoded><![CDATA[<p>can i hv ur chat id sudarmuthu.thanks<br />
vino</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: InfySEC staff</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544804</link>
		<dc:creator>InfySEC staff</dc:creator>
		<pubDate>Wed, 12 Aug 2009 17:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544804</guid>
		<description>Great hack. Congratulations on *hacking* all the flags! You have learned the priceless lesson. 

Let me go into a big more details of your hack, as it highlights the importance of fingerprinting: when performing a formal pentesting, it is crucial to have a clear picture of the entire site, including installed applications, location, version etc. 

Take phpMyAdmin for example, it is a very good bet to look for phpMyAdmin to break into the site when you are conducting a small-medium sized website. However, you need to figure out its path, there are couple ways for doing it: google hack, guess - base upon experience or learned information, bruteforce, learn it from page sources etc. (Note: the path is case sensitive on Linux, on phpmyadmin != phpMyAdmin) Once you figured out the path, then you will need to break into the it, by either applying known vulnerabilities (base upon its version), or attack its weak configuration. And hey, don&#039;t forget phpMyAdmin (as well other open source apps) are open source, which means you own their source code, so?....you know what I meant :)

Again, thanks for attending hackintosh and I wished you enjoyed the presentations &amp; ctf. It would be great if you can send me some feedback of how you thought about the event and what can be improved. 

Thanks!</description>
		<content:encoded><![CDATA[<p>Great hack. Congratulations on *hacking* all the flags! You have learned the priceless lesson. </p>
<p>Let me go into a big more details of your hack, as it highlights the importance of fingerprinting: when performing a formal pentesting, it is crucial to have a clear picture of the entire site, including installed applications, location, version etc. </p>
<p>Take phpMyAdmin for example, it is a very good bet to look for phpMyAdmin to break into the site when you are conducting a small-medium sized website. However, you need to figure out its path, there are couple ways for doing it: google hack, guess &#8211; base upon experience or learned information, bruteforce, learn it from page sources etc. (Note: the path is case sensitive on Linux, on phpmyadmin != phpMyAdmin) Once you figured out the path, then you will need to break into the it, by either applying known vulnerabilities (base upon its version), or attack its weak configuration. And hey, don&#8217;t forget phpMyAdmin (as well other open source apps) are open source, which means you own their source code, so?&#8230;.you know what I meant <img src='http://sudarmuthu.com/wpfiles/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Again, thanks for attending hackintosh and I wished you enjoyed the presentations &amp; ctf. It would be great if you can send me some feedback of how you thought about the event and what can be improved. </p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sudarmuthu (Sudar)</title>
		<link>http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544738</link>
		<dc:creator>sudarmuthu (Sudar)</dc:creator>
		<pubDate>Wed, 12 Aug 2009 09:21:23 +0000</pubDate>
		<guid isPermaLink="false">http://sudarmuthu.com/blog/2009/08/12/protect-your-phpmyadmin-folder-or.html#comment-544738</guid>
		<description>Protect your phpMyAdmin folder, otherwise you are asking for trouble. http://bit.ly/1QLxoa</description>
		<content:encoded><![CDATA[<p>Protect your phpMyAdmin folder, otherwise you are asking for trouble. <a href="http://bit.ly/1QLxoa" rel="nofollow">http://bit.ly/1QLxoa</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
