Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17867
| Path | csiph.com!xmission!news.snarked.org!news.linkpendium.com!news.linkpendium.com!panix!qz!not-for-mail |
|---|---|
| From | Eli the Bearded <*@eli.users.panix.com> |
| Newsgroups | comp.lang.php |
| Subject | go-pear backdoored |
| Date | Wed, 23 Jan 2019 22:23:56 +0000 (UTC) |
| Organization | Some absurd concept |
| Lines | 26 |
| Message-ID | <eli$1901231722@qaz.wtf> (permalink) |
| NNTP-Posting-Host | panix5.panix.com |
| X-Trace | reader2.panix.com 1548282236 315 166.84.1.5 (23 Jan 2019 22:23:56 GMT) |
| X-Complaints-To | abuse@panix.com |
| NNTP-Posting-Date | Wed, 23 Jan 2019 22:23:56 +0000 (UTC) |
| X-Liz | It's actually happened, the entire Internet is a massive game of Redcode |
| X-Motto | "Erosion of rights never seems to reverse itself." -- kenny@panix |
| X-US-Congress | Moronic Fucks. |
| X-Attribution | EtB |
| XFrom | is a real address |
| Encrypted | double rot-13 |
| User-Agent | Vectrex rn 2.1 (beta) |
| X-Comments | "'Pray that I don't alter the bargain further.' Welcome Darth Google." -- HonorableSoul |
| Xref | csiph.com comp.lang.php:17867 |
Show key headers only | View raw
`go-pear` goes _go pear-shaped_.
https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/
"If you have downloaded this go-pear.phar [package manager] in the
past six months, you should get a new copy of the same release
version from GitHub (pear/pearweb_phars) and compare file hashes,"
officials wrote on the site's blog. "If different, you may have the
infected file."
The officials didn't say when the hack of their Web server occurred
or precisely what the malicious version of go-pear.phar did to
infected systems. Initial indications, however, look serious. For
starters, the advice applies to anyone who has downloaded the
package manager in the past six months. That suggests the hack may
have occurred in the timeframe of last July, and no one noticed
either it or the tainted download until this week.
What's more, results from VirusTotal, the Google-owned malware
scanning service, suggest that the malicious PEAR download
installed a backdoor, possibly in the form of a Web shell, on
infected servers.
Elijah
------
is no longer an active PHP user
Back to comp.lang.php | Previous | Next — Next in thread | Find similar | Unroll thread
go-pear backdoored Eli the Bearded <*@eli.users.panix.com> - 2019-01-23 22:23 +0000 Re: go-pear backdoored Mi Na <ya12983@mail.com> - 2021-07-24 01:03 -0700
csiph-web