Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17867

go-pear backdoored

Path csiph.com!xmission!news.snarked.org!news.linkpendium.com!news.linkpendium.com!panix!qz!not-for-mail
From Eli the Bearded <*@eli.users.panix.com>
Newsgroups comp.lang.php
Subject go-pear backdoored
Date Wed, 23 Jan 2019 22:23:56 +0000 (UTC)
Organization Some absurd concept
Lines 26
Message-ID <eli$1901231722@qaz.wtf> (permalink)
NNTP-Posting-Host panix5.panix.com
X-Trace reader2.panix.com 1548282236 315 166.84.1.5 (23 Jan 2019 22:23:56 GMT)
X-Complaints-To abuse@panix.com
NNTP-Posting-Date Wed, 23 Jan 2019 22:23:56 +0000 (UTC)
X-Liz It's actually happened, the entire Internet is a massive game of Redcode
X-Motto "Erosion of rights never seems to reverse itself." -- kenny@panix
X-US-Congress Moronic Fucks.
X-Attribution EtB
XFrom is a real address
Encrypted double rot-13
User-Agent Vectrex rn 2.1 (beta)
X-Comments "'Pray that I don't alter the bargain further.' Welcome Darth Google." -- HonorableSoul
Xref csiph.com comp.lang.php:17867

Show key headers only | View raw


`go-pear` goes _go pear-shaped_.

https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/

     "If you have downloaded this go-pear.phar [package manager] in the
     past six months, you should get a new copy of the same release
     version from GitHub (pear/pearweb_phars) and compare file hashes,"
     officials wrote on the site's blog. "If different, you may have the
     infected file."

     The officials didn't say when the hack of their Web server occurred
     or precisely what the malicious version of go-pear.phar did to
     infected systems. Initial indications, however, look serious. For
     starters, the advice applies to anyone who has downloaded the
     package manager in the past six months. That suggests the hack may
     have occurred in the timeframe of last July, and no one noticed
     either it or the tainted download until this week.

     What's more, results from VirusTotal, the Google-owned malware
     scanning service, suggest that the malicious PEAR download
     installed a backdoor, possibly in the form of a Web shell, on
     infected servers. 

Elijah
------
is no longer an active PHP user

Back to comp.lang.php | Previous | NextNext in thread | Find similar | Unroll thread


Thread

go-pear backdoored Eli the Bearded <*@eli.users.panix.com> - 2019-01-23 22:23 +0000
  Re: go-pear backdoored Mi Na <ya12983@mail.com> - 2021-07-24 01:03 -0700

csiph-web