<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kirrus' Blog &#187; security</title>
	<atom:link href="http://kirrus.co.uk/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://kirrus.co.uk</link>
	<description>MindDump. Photos. And random ramblings.</description>
	<lastBuildDate>Mon, 26 Jul 2010 21:44:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>phpmyadmin in ubuntu now being exploited en-masse</title>
		<link>http://kirrus.co.uk/2009/07/phpmyadmin-in-ubuntu-now-being-exploited-en-masse/</link>
		<comments>http://kirrus.co.uk/2009/07/phpmyadmin-in-ubuntu-now-being-exploited-en-masse/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 13:00:15 +0000</pubDate>
		<dc:creator>Kirrus</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Ubuntu-UK Planet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://kirrus.co.uk/?p=279</guid>
		<description><![CDATA[Update: ubuntu patched this issue a couple of days after this post. If you&#8217;re reading, thanks guys! You just made my job a lot easier At some point, I might try to look at helping maintain this, and other packages like it in the ubuntu archive. No idea how, though a colleague may be able [...]]]></description>
			<content:encoded><![CDATA[<p>Update: ubuntu patched this issue a couple of days after this post. If you&#8217;re reading, thanks guys! You just made my job a lot easier <img src='http://kirrus.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>At some point, I might try to look at helping maintain this, and other packages like it in the ubuntu archive. No idea how, though a colleague may be able to help&#8230;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>The versions of phpmyadmin in ubuntu (at least Dapper &#8211; Intrepid) are susceptible to arbitrary code execution, as the web-server&#8217;s user. A bug<sup class='footnote'><a href='#fn-279-1' id='fnref-279-1'>1</a></sup> was reported on the 15th of June about this issue, and marked as high priority on the 21st.</p>
<p>The phpmyadmin team patched this problem in their software on<strong> May the 24th</strong>. <sup class='footnote'><a href='#fn-279-2' id='fnref-279-2'>2</a></sup></p>
<p>Debian patched this in their system on the 25th of June.</p>
<p>I tried talking to people on #ubuntu-security about this problem. They said &#8220;motu&#8221; and &#8220;we&#8217;re not interested, its in universe&#8221;. I tried talking to people in #motu, and they talked about work-arounds.</p>
<p>The main questions now are:</p>
<ul>
<li> Please can someone work on the bug?</li>
<li>Why did it take so long between upstream report and launchpad report?</li>
<li>Why has the bug been left to the point where it is getting automatically exploited, en-masse? <sup class='footnote'><a href='#fn-279-3' id='fnref-279-3'>3</a></sup></li>
</ul>
<div class='footnotes'>
<div class='footnotedivider'></div>
<ol>
<li id='fn-279-1'>https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/387215 <span class='footnotereverse'><a href='#fnref-279-1'>&#8617;</a></span></li>
<li id='fn-279-2'>http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php <span class='footnotereverse'><a href='#fnref-279-2'>&#8617;</a></span></li>
<li id='fn-279-3'>http://seclists.org/fulldisclosure/2009/Jul/0021.html <span class='footnotereverse'><a href='#fnref-279-3'>&#8617;</a></span></li>
</ol>
</div>
]]></content:encoded>
			<wfw:commentRss>http://kirrus.co.uk/2009/07/phpmyadmin-in-ubuntu-now-being-exploited-en-masse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
