To improve the security of your Raspberry Pi, I strongly recommend blocking external access to the phpMyAdmin web page.
To do this, simply edit the phpmyadmin.conf file.
First, in Terminal, type:
sudo nano /etc/apache2/conf-enabled/phpmyadmin.conf
now add the three lines shown in bold
# phpMyAdmin default Apache configurationAlias /phpmyadmin /usr/share/phpmyadmin<Directory /usr/share/phpmyadmin> #do not allow access from the outside world! Order Deny,Allow Deny from All Allow from 172.16.1.222 Options SymLinksIfOwnerMatch DirectoryIndex index.php <IfModule mod_php5.c> <IfModule mod_mime.c> AddType application/x-httpd-php .php </IfModule> <FilesMatch ".+\.php$"> SetHandler application/x-httpd-php </FilesMatch> php_value include_path . php_admin_value upload_tmp_dir /var/lib/phpmyadmin/tmp php_admin_value open_basedir /usr/share/phpmyadmin/:/etc/phpmyadmin/:/var/lib/phpmyadmin/:/usr/share/php/php-gettext/:/usr/share/php/php-php-gettext/:/usr/share/javascript/:/usr/share/php/tcpdf/:/usr/share/doc/phpmyadmin/:/usr/share/php/phpseclib/ php_admin_value mbstring.func_overload 0 </IfModule> <IfModule mod_php.c> <IfModule mod_mime.c> AddType application/x-httpd-php .php </IfModule> <FilesMatch ".+\.php$"> SetHandler application/x-httpd-php </FilesMatch> php_value include_path . php_admin_value upload_tmp_dir /var/lib/phpmyadmin/tmp php_admin_value open_basedir /usr/share/phpmyadmin/:/etc/phpmyadmin/:/var/lib/phpmyadmin/:/usr/share/php/php-gettext/:/usr/share/php/php-gettext/:/usr/share/javascript/:/usr/share/php/tcpdf/:/usr/share/doc/phpmyadmin/:/usr/share/php/phpseclib/ php_admin_value mbstring.func_overload 0 </IfModule></Directory># Authorize for setup<Directory /usr/share/phpmyadmin/setup> <IfModule mod_authz_core.c> <IfModule mod_authn_file.c> AuthType Basic AuthName "phpMyAdmin Setup" AuthUserFile /etc/phpmyadmin/htpasswd.setup </IfModule> Require valid-user </IfModule></Directory># Disallow web access to directories that don't need it<Directory /usr/share/phpmyadmin/templates> Require all denied</Directory><Directory /usr/share/phpmyadmin/libraries> Require all denied</Directory><Directory /usr/share/phpmyadmin/setup/lib> Require all denied</Directory>
this restricts access to the phpMyAdmin web page to the machine with IP address 172.16.1.222 only
Now press CTRL+X to exit and save (you will be asked to confirm with the ENTER key)
Finally, to apply the change, restart the Apache service by typing
sudo service apache2 restart
Enjoy!
