Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17867
| From | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | go-pear backdoored |
| Date | 2019-01-23 22:23 +0000 |
| Organization | Some absurd concept |
| Message-ID | <eli$1901231722@qaz.wtf> (permalink) |
`go-pear` goes _go pear-shaped_.
https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/
"If you have downloaded this go-pear.phar [package manager] in the
past six months, you should get a new copy of the same release
version from GitHub (pear/pearweb_phars) and compare file hashes,"
officials wrote on the site's blog. "If different, you may have the
infected file."
The officials didn't say when the hack of their Web server occurred
or precisely what the malicious version of go-pear.phar did to
infected systems. Initial indications, however, look serious. For
starters, the advice applies to anyone who has downloaded the
package manager in the past six months. That suggests the hack may
have occurred in the timeframe of last July, and no one noticed
either it or the tainted download until this week.
What's more, results from VirusTotal, the Google-owned malware
scanning service, suggest that the malicious PEAR download
installed a backdoor, possibly in the form of a Web shell, on
infected servers.
Elijah
------
is no longer an active PHP user
Back to comp.lang.php | Previous | Next — Next in thread | Find similar | Unroll thread
go-pear backdoored Eli the Bearded <*@eli.users.panix.com> - 2019-01-23 22:23 +0000 Re: go-pear backdoored Mi Na <ya12983@mail.com> - 2021-07-24 01:03 -0700
csiph-web