<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pgadmin on Siti</title><link>https://siti.pages.dev/tags/pgadmin/</link><description>Recent content in Pgadmin on Siti</description><generator>Hugo</generator><language>id</language><lastBuildDate>Mon, 23 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://siti.pages.dev/tags/pgadmin/index.xml" rel="self" type="application/rss+xml"/><item><title>Exposed Database Panels: Adminer, phpMyAdmin &amp; pgAdmin</title><link>https://siti.pages.dev/docs/exposed-db-panels/</link><pubDate>Mon, 23 Feb 2026 00:00:00 +0000</pubDate><guid>https://siti.pages.dev/docs/exposed-db-panels/</guid><description>&lt;h2 id="daftar-isi"&gt;Daftar Isi&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#bab-1--menemukan-panel-yang-terekspos"&gt;Bab 1 — Menemukan Panel yang Terekspos&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#11-apa-itu-adminer--phpmyadmin"&gt;1.1 Apa itu Adminer &amp;amp; phpMyAdmin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#12-mengapa-sering-terekspos"&gt;1.2 Mengapa Sering Terekspos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#13-dorking-google"&gt;1.3 Dorking: Google&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#14-dorking-shodan"&gt;1.4 Dorking: Shodan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#15-dorking-fofa--censys--zoomeye"&gt;1.5 Dorking: FOFA / Censys / ZoomEye&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#16-nuclei-templates"&gt;1.6 Nuclei Templates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#17-manual-discovery-via-path-bruteforce"&gt;1.7 Manual Discovery via Path Bruteforce&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#bab-2--eksploitasi-adminer"&gt;Bab 2 — Eksploitasi Adminer&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#21-versi--kerentanan"&gt;2.1 Versi &amp;amp; Kerentanan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#22-default--weak-credentials"&gt;2.2 Default / Weak Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#23-cve-2021-21311--ssrf"&gt;2.3 CVE-2021-21311 — SSRF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#24-adminer-file-read-rogue-mysql-server"&gt;2.4 Adminer File Read (Rogue MySQL Server)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#25-login-tanpa-password-mysql-empty-root"&gt;2.5 Login tanpa Password (MySQL Empty Root)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#26-post-login-database-ke-shell"&gt;2.6 Post-Login: Database ke Shell&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#bab-3--eksploitasi-phpmyadmin"&gt;Bab 3 — Eksploitasi phpMyAdmin&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#31-versi--kerentanan"&gt;3.1 Versi &amp;amp; Kerentanan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#32-default--weak-credentials"&gt;3.2 Default / Weak Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#33-cve-2018-12613--local-file-inclusion"&gt;3.3 CVE-2018-12613 — Local File Inclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#34-cve-2016-5734--rce-via-preg_replace"&gt;3.4 CVE-2016-5734 — RCE via preg_replace&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#35-post-login-sql-query-ke-webshell"&gt;3.5 Post-Login: SQL Query ke Webshell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#36-post-login-select-into-outfile"&gt;3.6 Post-Login: SELECT INTO OUTFILE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#37-post-login-general-log-trick"&gt;3.7 Post-Login: General Log Trick&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#bab-4--post-exploitation"&gt;Bab 4 — Post-Exploitation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#41-dari-database-access-ke-data-dump"&gt;4.1 Dari Database Access ke Data Dump&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#42-dari-database-ke-shell-rce"&gt;4.2 Dari Database ke Shell (RCE)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#43-privilege-escalation-dari-mysql-user"&gt;4.3 Privilege Escalation dari MySQL User&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#44-pivot-ke-aplikasi-web"&gt;4.4 Pivot ke Aplikasi Web&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#45-checklist-ringkasan"&gt;4.5 Checklist Ringkasan&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#bab-5--postgresql-pgadmin--eksploitasi-via-sql"&gt;Bab 5 — PostgreSQL: pgAdmin &amp;amp; Eksploitasi via SQL&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#51-panel-yang-mengekspos-postgresql"&gt;5.1 Panel yang Mengekspos PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#52-menemukan-pgadmin-yang-terekspos"&gt;5.2 Menemukan pgAdmin yang Terekspos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#53-adminer--postgresql"&gt;5.3 Adminer + PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#54-copy-from-program--rce-langsung"&gt;5.4 COPY FROM PROGRAM — RCE Langsung&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#55-file-read--write-via-large-object"&gt;5.5 File Read &amp;amp; Write via Large Object&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#56-file-read-via-pg_read_file--pg_ls_dir"&gt;5.6 File Read via pg_read_file &amp;amp; pg_ls_dir&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#57-rce-via-procedural-languages-plpythonu--plperlu"&gt;5.7 RCE via Procedural Languages (plpythonu / plperlu)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#58-extension-abuse-dblink"&gt;5.8 Extension Abuse: dblink&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#59-extension-abuse-adminpack--pg_execute_server_program"&gt;5.9 Extension Abuse: adminpack &amp;amp; pg_execute_server_program&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#510-privilege-escalation-di-postgresql"&gt;5.10 Privilege Escalation di PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://siti.pages.dev/docs/exposed-db-panels/#511-checklist-postgresql"&gt;5.11 Checklist PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="bab-1--menemukan-panel-yang-terekspos"&gt;Bab 1 — Menemukan Panel yang Terekspos&lt;/h2&gt;
&lt;h3 id="11-apa-itu-adminer--phpmyadmin"&gt;1.1 Apa itu Adminer &amp;amp; phpMyAdmin&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Tool&lt;/th&gt;
 &lt;th&gt;Deskripsi&lt;/th&gt;
 &lt;th&gt;File&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Adminer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Database management dalam 1 file PHP. Support MySQL, PostgreSQL, SQLite, MS SQL, Oracle&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;adminer.php&lt;/code&gt; (single file)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;phpMyAdmin&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Web interface untuk MySQL/MariaDB. Lebih lengkap, lebih berat&lt;/td&gt;
 &lt;td&gt;Folder &lt;code&gt;/phpmyadmin/&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Keduanya digunakan developer untuk mengelola database via browser. Masalahnya — sering &lt;strong&gt;lupa dihapus&lt;/strong&gt; atau &lt;strong&gt;tidak dilindungi&lt;/strong&gt; di production server.&lt;/p&gt;</description></item></channel></rss>