TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

PhpMyAdmin 3.3.9 is released

8 点作者 thefox超过 14 年前

2 条评论

davidu超过 14 年前
PhpMyAdmin is a really great tool. It's also a really great tool with a history of exceptionally serious security issues.<p>If you run PhpMyAdmin on an Internet-accessible server please please please add some security above and beyond what the application provides.<p>1) Use web-server based IP-address based restrictions to allow/deny connections only from trusted hosts.<p>2) Please run it over HTTPS, as it passes mysql passwords around plaintext when you use cookie or www-auth authentication.<p>3) Use an additional .htaccess in front of PhpMyAdmin's basic www-auth.<p>4) Do not host it at /phpmyadmin in your docroot.<p>5) Maybe consider running it only on a virtualhost listening on a different port.
notyourwork超过 14 年前
/me wishes our Security group did not dislike phpMyAdmin as I would love to fire this up and see the new features.