diff --git a/Documentation.html b/Documentation.html index 987ed17d30..2f0aafaa1a 100644 --- a/Documentation.html +++ b/Documentation.html @@ -312,7 +312,7 @@ rm -rf config # remove not needed directory authentication mode.
robots.txt file in root of
- your webserver or limit access by web server configuration. You can
- find example .htaccess file which can help you achieve
- this in contrib directory in phpMyAdmin.
+ your webserver or limit access by web server configuration, see
+ FAQ 1.42.
@@ -480,7 +479,7 @@ GRANT ALL PRIVILEGES ON user_base.* TO 'real_user'@localhost IDENTIFIED BY 'real
1.35.
Options FollowSymLinks and AllowOverride
FileInfo enabled for directory where phpMyAdmin is installed and
you need mod_rewrite to be enabled. Then you just need to create following
- .htaccess file in root folder of phpMyAdmin installation
+ .htaccess file in root folder of phpMyAdmin installation
(don't forget to change directory name inside of it):
@@ -3183,6 +3182,35 @@ ProxyPassReverseCookiePath /%7Euser/phpmyadmin /mirror/fooThe MySQL server's privilege tables are not up to date, you need to run the mysql_upgrade command on the server.
++ 1.42 How can I prevent robots from accessing phpMyAdmin?
+ +You can add various rules to .htaccess to filter access +based on user agent field. This is quite easy to circumvent, but could prevent at least +some robots accessing your installation.
+ ++RewriteEngine on + +# Allow only GET and POST verbs +RewriteCond %{REQUEST_METHOD} !^(GET|POST)$ [NC,OR] + +# Ban Typical Vulnerability Scanners and others +# Kick out Script Kiddies +RewriteCond %{HTTP_USER_AGENT} ^(java|curl|wget).* [NC,OR] +RewriteCond %{HTTP_USER_AGENT} ^.*(libwww-perl|curl|wget|python|nikto|wkito|pikto|scan|acunetix).* [NC,OR] +RewriteCond %{HTTP_USER_AGENT} ^.*(winhttp|HTTrack|clshttp|archiver|loader|email|harvest|extract|grab|miner).* [NC,OR] + +# Ban Search Engines, Crawlers to your administrative panel +# No reasons to access from bots +# Ultimately Better than the useless robots.txt +# Did google respect robots.txt? +# Try google: intitle:phpMyAdmin intext:"Welcome to phpMyAdmin *.*.*" intext:"Log in" -wiki -forum -forums -questions intext:"Cookies must be enabled" +RewriteCond %{HTTP_USER_AGENT} ^.*(AdsBot-Google|ia_archiver|Scooter|Ask.Jeeves|Baiduspider|Exabot|FAST.Enterprise.Crawler|FAST-WebCrawler|www\.neomo\.de|Gigabot|Mediapartners-Google|Google.Desktop|Feedfetcher-Google|Googlebot|heise-IT-Markt-Crawler|heritrix|ibm.com\cs/crawler|ICCrawler|ichiro|MJ12bot|MetagerBot|msnbot-NewsBlogs|msnbot|msnbot-media|NG-Search|lucene.apache.org|NutchCVS|OmniExplorer_Bot|online.link.validator|psbot0|Seekbot|Sensis.Web.Crawler|SEO.search.Crawler|Seoma.\[SEO.Crawler\]|SEOsearch|Snappy|www.urltrends.com|www.tkl.iis.u-tokyo.ac.jp/~crawler|SynooBot|crawleradmin.t-info@telekom.de|TurnitinBot|voyager|W3.SiteSearch.Crawler|W3C-checklink|W3C_Validator|www.WISEnutbot.com|yacybot|Yahoo-MMCrawler|Yahoo\!.DE.Slurp|Yahoo\!.Slurp|YahooSeeker).* [NC] +RewriteRule .* - [F] ++ +Configuration
@@ -3584,7 +3612,7 @@ have either the APC extension This depends on your system.
If you're running a server which cannot be accessed by other people, it's sufficient to use the directory protection bundled with your webserver - (with Apache you can use .htaccess files, for example).
+ (with Apache you can use .htaccess files, for example).
If other people have telnet access to your server, you should use phpMyAdmin's HTTP or cookie authentication features.
@@ -3628,7 +3656,7 @@ have either the APC extension are wrong.
If you have existing rules from an old .htaccess file, you can take them +
If you have existing rules from an old .htaccess file, you can take them and add a username between the 'deny'/'allow' and 'from' strings. Using the username wildcard of '%' would be a major benefit here if your installation is suited to using it. Then diff --git a/contrib/htaccess b/contrib/htaccess deleted file mode 100644 index 6eebe01013..0000000000 --- a/contrib/htaccess +++ /dev/null @@ -1,19 +0,0 @@ -RewriteEngine on - -# Allow only GET and POST verbs -RewriteCond %{REQUEST_METHOD} !^(GET|POST)$ [NC,OR] - -# Ban Typical Vulnerability Scanners and others -# Kick out Script Kiddies -RewriteCond %{HTTP_USER_AGENT} ^(java|curl|wget).* [NC,OR] -RewriteCond %{HTTP_USER_AGENT} ^.*(libwww-perl|curl|wget|python|nikto|wkito|pikto|scan|acunetix).* [NC,OR] -RewriteCond %{HTTP_USER_AGENT} ^.*(winhttp|HTTrack|clshttp|archiver|loader|email|harvest|extract|grab|miner).* [NC,OR] - -# Ban Search Engines, Crawlers to your administrative panel -# No reasons to access from bots -# Ultimately Better than the useless robots.txt -# Did google respect robots.txt? -# Try google: intitle:phpMyAdmin intext:"Welcome to phpMyAdmin *.*.*" intext:"Log in" -wiki -forum -forums -questions intext:"Cookies must be enabled" -RewriteCond %{HTTP_USER_AGENT} ^.*(AdsBot-Google|ia_archiver|Scooter|Ask.Jeeves|Baiduspider|Exabot|FAST.Enterprise.Crawler|FAST-WebCrawler|www\.neomo\.de|Gigabot|Mediapartners-Google|Google.Desktop|Feedfetcher-Google|Googlebot|heise-IT-Markt-Crawler|heritrix|ibm.com\cs/crawler|ICCrawler|ichiro|MJ12bot|MetagerBot|msnbot-NewsBlogs|msnbot|msnbot-media|NG-Search|lucene.apache.org|NutchCVS|OmniExplorer_Bot|online.link.validator|psbot0|Seekbot|Sensis.Web.Crawler|SEO.search.Crawler|Seoma.\[SEO.Crawler\]|SEOsearch|Snappy|www.urltrends.com|www.tkl.iis.u-tokyo.ac.jp/~crawler|SynooBot|crawleradmin.t-info@telekom.de|TurnitinBot|voyager|W3.SiteSearch.Crawler|W3C-checklink|W3C_Validator|www.WISEnutbot.com|yacybot|Yahoo-MMCrawler|Yahoo\!.DE.Slurp|Yahoo\!.Slurp|YahooSeeker).* [NC] -RewriteRule .* - [F] -