Pull to refresh
0

php.net скомпрометирован

Reading time 1 min
Views 15K
Несколько часов назад стало известно, что известный веб-сайт для разработчиков PHP — php.net скомпрометирован вредоносным содержимым (JavaScript) и осуществляет доставку вредоносного ПО для пользователей через набор эксплойтов.

We are continuing to work through the repercussions of the php.net malware issue described in a news post earlier today. As part of this, the php.net systems team have audited every server operated by php.net, and have found that two servers were compromised: the server which hosted the www.php.net, static.php.net and git.php.net domains, and was previously suspected based on the JavaScript malware, and the server hosting bugs.php.net. The method by which these servers were compromised is unknown at this time.

A further update on php.net



One of our research tools flagged php.net as distributing malware. The site appears to have been compromised and had some of its javascript altered to exploit vulnerable systems visiting the website, instead of ad network vector that we typically see in more popular sites.

Barracuda Labs

В заявлении представителей php.net говорится, что веб-сайт попал в «темный список» Google и фиксировался как подозрительный сервисом safe browsing service, после чего администраторы начали расследование случая компрометации.

Вредоносное ПО, которое устанавливалось пользователям:

VT sample1
VT sample2
VT sample3
VT sample4
VT sample5
Tags:
Hubs:
+24
Comments 12
Comments Comments 12

Articles

Information

Website
www.esetnod32.ru
Registered
Founded
Employees
1,001–5,000 employees
Location
Словакия