by williamconley » Tue Jan 15, 2013 9:13 pm
phpMyAdmin should be locked via apache (locking the folder to remove any possible access). this requires a sep user/pass for that folder (which is not a bad thing, after all regular users shouldn't be in there anyway!). We lock ALL servers we build in this manner. It is a mere matter of creating a password file with httpd2 and configuring the apache conf file for the site.
Ordinarily, we simply whitelist the servers. We have also begun adding our Dynamic Good Guys to all client servers automatically. We only have to sell it two more times before we release it as an installable (svn down, install ... done).
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294