<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: pmafind</title>
	<atom:link href="http://blog.arithm.com/2007/07/27/pmafind/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.arithm.com/2007/07/27/pmafind/</link>
	<description>Software.  Politics.  Tinfoil hat conjecture.</description>
	<lastBuildDate>Mon, 30 Jan 2012 09:08:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: deadman</title>
		<link>http://blog.arithm.com/2007/07/27/pmafind/comment-page-1/#comment-139</link>
		<dc:creator>deadman</dc:creator>
		<pubDate>Thu, 10 Jan 2008 08:31:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.arithm.com/2007/07/27/pmafind/#comment-139</guid>
		<description>This script is designed by someone to look into websites where phpmyadmin and mysql was not configured properly.

Some projects out there like XAMPP,defaults after installing to settings that leave the server open for attacks. Specifically phpmyadmin.

When XAMPP installs mysql, it creates a root account with no password. And sets up phpmyadmin to access the mysql server through the root user, which does not need a password. When such access is available, the attacker can easily get into mysql and through it create a file that will give the attacker full shell access.

I&#039;ve tried it myself and it works.

This is not a vulnerability or weaknesses on software, but through the ignorant use of software by users out there who have no idea what they are working on.

XAMPP is a great project. The exploit is not tied to that project. It was provided as an example.</description>
		<content:encoded><![CDATA[<p>This script is designed by someone to look into websites where phpmyadmin and mysql was not configured properly.</p>
<p>Some projects out there like XAMPP,defaults after installing to settings that leave the server open for attacks. Specifically phpmyadmin.</p>
<p>When XAMPP installs mysql, it creates a root account with no password. And sets up phpmyadmin to access the mysql server through the root user, which does not need a password. When such access is available, the attacker can easily get into mysql and through it create a file that will give the attacker full shell access.</p>
<p>I&#8217;ve tried it myself and it works.</p>
<p>This is not a vulnerability or weaknesses on software, but through the ignorant use of software by users out there who have no idea what they are working on.</p>
<p>XAMPP is a great project. The exploit is not tied to that project. It was provided as an example.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

