Forum Moderators: open

Message Too Old, No Replies

PMAFind

Looks for PHP and MySQL vulnerabilities

         

GaryK

3:12 pm on Oct 2, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It comes in two flavors:

PMAFind
216.13.18.***

pmafind
216.13.18.***

MatthewHSE referred to it in a thread [webmasterworld.com] that got no replies at all.

All it does it look for PHP and MySQL vulnerabilities:

/admin/main.php
/admin/phpmyadmin/main.php
/db/main.php
/mysql-admin/main.php
/mysql/main.php
/phpMyAdmin-2.2.3/main.php
/phpMyAdmin-2.5.1/main.php
/phpmyadmin/main.php
/PMA/main.php
/web/phpMyAdmin/main.php

I think it's based on the currently inactive phpMyAuth [sourceforge.net] class (aka PMA) for PHP from SourceForge. It's a web site user authentication and authorization system. I suppose it could also be used to probe other sites for related files to see what sort of status the request returns. If it gets an access denied status message it might try and break in, otherwise it just moves on to the next site.

[edited by: volatilegx at 2:58 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP addresses [/edit]

jatar_k

6:39 pm on Oct 3, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



I think the PMA refers to phpmyadmin find

it seems to look specifically for phpmyadmin, though it was very hard to find any info about it on the web at all.

MLHmptn

6:33 am on Oct 8, 2005 (gmt 0)

10+ Year Member



I just seen this in my logs today as well.

80.134.213.*** - - [05/Oct/2005:09:11:35 -0700] "GET /PMA/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:35 -0700] "GET /phpmyadmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /mysql/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /db/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:36 -0700] "GET /dbadmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:37 -0700] "GET /web/phpMyAdmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:37 -0700] "GET /mysql-admin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:38 -0700] "GET /phpmyadmin2/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:38 -0700] "GET /mysqladmin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /mysql-admin/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:39 -0700] "GET /phpMyAdmin-2.5.6/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.5.4/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.5.1/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.2.3/main.php HTTP/1.1" 404 967 "-" "PMAFind"
80.134.213.*** - - [05/Oct/2005:09:11:40 -0700] "GET /phpMyAdmin-2.2.6/main.php HTTP/1.1" 404 967 "-" "PMAFind"

Must be some new exploit for phpmyAdmin that has no password protected folders.

Interesting to say the least....

[edited by: volatilegx at 2:59 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP addresses [/edit]

Poolart

12:38 pm on Oct 14, 2005 (gmt 0)



Same here. I found this also on my servers today

66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /phpmyadmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /PMA/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /mysql/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /admin/main.php HTTP/1.0" 401 1310
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /db/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:01 +0200] "GET /dbadmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /web/phpMyAdmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/pma/main.php HTTP/1.0" 401 1314
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/phpmyadmin/main.php HTTP/1.0" 401 1321
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /admin/mysql/main.php HTTP/1.0" 401 1316
66.148.224.*** - - [13/Oct/2005:14:40:02 +0200] "GET /mysql-admin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /phpmyadmin2/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /mysqladmin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /mysql-admin/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:03 +0200] "GET /main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.6/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.4/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.5.1/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.2.3/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:04 +0200] "GET /phpMyAdmin-2.2.6/main.php HTTP/1.0" 404 1059
66.148.224.*** - - [13/Oct/2005:14:40:05 +0200] "GET /myadmin/main.php HTTP/1.0" 404 1059

[edited by: volatilegx at 3:00 pm (utc) on Oct. 14, 2005]
[edit reason] obscured IP address [/edit]