Full article here:
Sophos
Apparently the korean mirror cdnetworks-kr-1 was serving an infected version of phpMyAdmin 3.5.2.2 over the last week-end which was downloaded about 400 times.
Identifying whether you've been affected or not is quite easy:
Quote:
If you're a pgpMyAdmin user, it's well worth checking your install for the rogue file server_sync.php. (There shouldn't a file of that name, though there is an official server_synchronize.php component in 3.5.2.2.)
Also, re-download the distribution file and verify that your copy of js/cross_framing_protection.js is correct.T
|
regards myrti