Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Attacks On Internet’s “Weakest Link” Continue Unabated.

by The Gurus
November 12, 2019
in Featured, Network Security
Cloud Security motherboard
Share on FacebookShare on Twitter

New threat intelligence from F5 Labs has highlighted the increasing vulnerability of a programming language used in over 80% of the world’s websites.

According to F5 Labs’ data partner Loryka, 81% of malicious traffic monitored in the wild in 2018 was PHP-related. This represents a 23% rise compared to 2017. Monitoring focused on initial reconnaissance campaigns looking for admin surfaces to compromise as part of a broader attack chain.

Featuring in the first instalment F5 Lab’s Application Protection Report 2019, the research also notes that PHP accounted for 68% of all of 2018’s published exploits on the Exploit Database.

“The volume and relentless nature of PHP exploits are alarming but unsurprising,” said Sander Vinberg, Threat Research Evangelist, F5 Labs.

“Based on our research, we predict that it will remain one of the Internet’s weakest links and broadest attack surfaces for the foreseeable future.”

As a part of its analysis, F5 Labs also shed light on specific PHP attack tactics.

Loryka’s sensors identify connection attempts and capture data such as source IP and target URL. Attackers often cycle through billions of targets looking for opportunities to attack, so the target domain or IP address is not significant. However, the back half of the target URL contains the target file or path. This is the specific location on a web server that the attacker is targeting across all their target IPs. It also reveals a lot about an attacker’s goals and tactics.

For example, Loryka noted that a huge portion of traffic focused on just seven paths or filenames. All seven are commonly used for managing phpMyAdmin (also known as PMA), which is a PHP web application used for managing MySQL databases.

42% of the 1.5M unique events targeting more than 100,000 different URL were aimed at one of the following:

www.example.com/PMA2011/
www.example.com/pma2011/
www.example.com/PMA2012/
www.example.com/phpmyadmin3/
www.example.com/pma2012/
www.example.com/phpmyadmin4/
www.example.com/phpmyadmin2/

The traffic volume targeting these was found to be almost identical from path to path, with less than a 3% difference between most and least frequent volume. The timing of the campaigns targeting these paths was also close to identical, with traffic spiking in coordination.

On closer inspection, F5 Labs discovered that 87% of the traffic pointed at the common phpMyAdmin paths stemmed from just two IPs out of the 66,000 IPs hitting Loryka’s sensors. These two IPs represented 37% of all monitored traffic in 2018. All traffic from the compromised IPs pointed at the seven PMA paths. No other single IP matched this volume of traffic or replicated its patterns – even when targeting the same paths.

Interestingly, the two IPs came from systems based on a North American university campus.

“Basically, unknown actors used a small number of compromised systems on university networks to look for specific targets: old and probably neglected MySQL databases with weak authentication,” Vinberg explained.

“These actors have defined a narrow set of target parameters but are scanning the entire web from a small number of addresses—and are not trying too hard to cover their tracks. Given that SQL injection was the most common PHP attack, it seems that the threat landscape is going to look similar this year.”

Vinberg added that mitigating the risk from these kind of campaigns should be relatively straightforward – provided system owners are aware of what is on their network.

“Whitelisting authentication pages for admin surfaces is an easy way to prevent a recon campaign of this nature from escalating,” he said.

“A robust access control program with strong passwords or multifactor authentication would also mitigate the risk of credential stuffing or escalation from a phishing campaign that might follow reconnaissance activities.”

F5 Lab’s PHP analysis is the first chapter of the Application Protection Report 2019. Additional instalments will be published throughout the year.

Share1Tweet
Previous Post

Future Proofing Cybersecurity – Securing Against An Arsenal Of New Technology.

Next Post

Automation Will Improve Security Function,

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol