Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17867 > unrolled thread
| Started by | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| First post | 2019-01-23 22:23 +0000 |
| Last post | 2021-07-24 01:03 -0700 |
| Articles | 2 — 2 participants |
Back to article view | Back to comp.lang.php
go-pear backdoored Eli the Bearded <*@eli.users.panix.com> - 2019-01-23 22:23 +0000
Re: go-pear backdoored Mi Na <ya12983@mail.com> - 2021-07-24 01:03 -0700
| From | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| Date | 2019-01-23 22:23 +0000 |
| Subject | go-pear backdoored |
| Message-ID | <eli$1901231722@qaz.wtf> |
`go-pear` goes _go pear-shaped_.
https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/
"If you have downloaded this go-pear.phar [package manager] in the
past six months, you should get a new copy of the same release
version from GitHub (pear/pearweb_phars) and compare file hashes,"
officials wrote on the site's blog. "If different, you may have the
infected file."
The officials didn't say when the hack of their Web server occurred
or precisely what the malicious version of go-pear.phar did to
infected systems. Initial indications, however, look serious. For
starters, the advice applies to anyone who has downloaded the
package manager in the past six months. That suggests the hack may
have occurred in the timeframe of last July, and no one noticed
either it or the tainted download until this week.
What's more, results from VirusTotal, the Google-owned malware
scanning service, suggest that the malicious PEAR download
installed a backdoor, possibly in the form of a Web shell, on
infected servers.
Elijah
------
is no longer an active PHP user
[toc] | [next] | [standalone]
| From | Mi Na <ya12983@mail.com> |
|---|---|
| Date | 2021-07-24 01:03 -0700 |
| Message-ID | <c11e41bc-9063-4dd6-a5af-c55501ccec08n@googlegroups.com> |
| In reply to | #17867 |
Eli the Bearded kirjutas neljapΓ€ev, 24. jaanuar 2019 kl 00:24:02 UTC+2: > `go-pear` goes _go pear-shaped_. > > https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/ > > "If you have downloaded this go-pear.phar [package manager] in the > past six months, you should get a new copy of the same release > version from GitHub (pear/pearweb_phars) and compare file hashes," > officials wrote on the site's blog. "If different, you may have the > infected file." > > The officials didn't say when the hack of their Web server occurred > or precisely what the malicious version of go-pear.phar did to > infected systems. Initial indications, however, look serious. For > starters, the advice applies to anyone who has downloaded the > package manager in the past six months. That suggests the hack may > have occurred in the timeframe of last July, and no one noticed > either it or the tainted download until this week. > > What's more, results from VirusTotal, the Google-owned malware > scanning service, suggest that the malicious PEAR download > installed a backdoor, possibly in the form of a Web shell, on > infected servers. > > Elijah > ------ > is no longer an active PHP user ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ ποΈ
[toc] | [prev] | [standalone]
Back to top | Article view | comp.lang.php
csiph-web