Forum Moderators: open
PMAFind
216.13.18.***
pmafind
216.13.18.***
MatthewHSE referred to it in a thread [webmasterworld.com] that got no replies at all.
All it does it look for PHP and MySQL vulnerabilities:
/admin/main.php
/admin/phpmyadmin/main.php
/db/main.php
/mysql-admin/main.php
/mysql/main.php
/phpMyAdmin-2.2.3/main.php
/phpMyAdmin-2.5.1/main.php
/phpmyadmin/main.php
/PMA/main.php
/web/phpMyAdmin/main.php
I think it's based on the currently inactive phpMyAuth [sourceforge.net] class (aka PMA) for PHP from SourceForge. It's a web site user authentication and authorization system. I suppose it could also be used to probe other sites for related files to see what sort of status the request returns. If it gets an access denied status message it might try and break in, otherwise it just moves on to the next site.
[edited by: volatilegx at 2:58 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP addresses [/edit]
80.134.213.*** - - [05/Oct/2005:09:11:35 -0700] "GET /PMA/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:35 -0700] "GET /phpmyadmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /mysql/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /db/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /dbadmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:37 -0700] "GET /web/phpMyAdmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:37 -0700] "GET /mysql-admin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:38 -0700] "GET /phpmyadmin2/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:38 -0700] "GET /mysqladmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /mysql-admin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /phpMyAdmin-2.5.6/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.5.4/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.5.1/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.2.3/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.2.6/main.php HTTP/1.1" 404 967 "-" "PMAFind"
Must be some new exploit for phpmyAdmin that has no password protected folders.
Interesting to say the least....
[edited by: volatilegx at 2:59 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP addresses [/edit]
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /phpmyadmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /PMA/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /mysql/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /admin/main.php HTTP/1.0" 401 1310
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /db/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /dbadmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /web/phpMyAdmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/pma/main.php HTTP/1.0" 401 1314
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/phpmyadmin/main.php HTTP/1.0" 401 1321
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/mysql/main.php HTTP/1.0" 401 1316
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /mysql-admin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /phpmyadmin2/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /mysqladmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /mysql-admin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.6/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.4/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.1/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.2.3/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.2.6/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:05 +0200] "GET /myadmin/main.php HTTP/1.0" 404 1059
[edited by: volatilegx at 3:00 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP address [/edit]