Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17867

go-pear backdoored

From Eli the Bearded <*@eli.users.panix.com>
Newsgroups comp.lang.php
Subject go-pear backdoored
Date 2019-01-23 22:23 +0000
Organization Some absurd concept
Message-ID <eli$1901231722@qaz.wtf> (permalink)

Show all headers | View raw


`go-pear` goes _go pear-shaped_.

https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/

     "If you have downloaded this go-pear.phar [package manager] in the
     past six months, you should get a new copy of the same release
     version from GitHub (pear/pearweb_phars) and compare file hashes,"
     officials wrote on the site's blog. "If different, you may have the
     infected file."

     The officials didn't say when the hack of their Web server occurred
     or precisely what the malicious version of go-pear.phar did to
     infected systems. Initial indications, however, look serious. For
     starters, the advice applies to anyone who has downloaded the
     package manager in the past six months. That suggests the hack may
     have occurred in the timeframe of last July, and no one noticed
     either it or the tainted download until this week.

     What's more, results from VirusTotal, the Google-owned malware
     scanning service, suggest that the malicious PEAR download
     installed a backdoor, possibly in the form of a Web shell, on
     infected servers. 

Elijah
------
is no longer an active PHP user

Back to comp.lang.php | Previous | NextNext in thread | Find similar | Unroll thread


Thread

go-pear backdoored Eli the Bearded <*@eli.users.panix.com> - 2019-01-23 22:23 +0000
  Re: go-pear backdoored Mi Na <ya12983@mail.com> - 2021-07-24 01:03 -0700

csiph-web