phpMyAdmin scans--what signatures should I block?
I have a Fail2ban setup that blocks known attack signatures. These signatures match accesses to files like "/muieblackcat" and user agents such as "ZmEu". I recently added a more generic signature that matches all accesses containing "/scripts/setup.php".
What other signatures do I need to block?
–DragonLord
2 Replies
If you don't have the target, it's just more Internet noise to ignore.
@vonskippy:
Why?
If you don't have the target, it's just more Internet noise to ignore.
I just took down PHPmyAdmin today. If you don't have what's trying to be hacked, or if you don't have a vulnerability, just ignore it as random internet noise. That happens.