Attackers Target PHP Git Server to Backdoor Source Code

  /     /     /  
Publicated : 23/11/2024   Category : security


Attackers Target PHP Git Server to Backdoor Source Code


The PHP maintainers have decided to make GitHub the official source for PHP repositories going forward.



Attackers have breached the official PHP Git server and infected its code base, PHP developers and maintainers report. They have decided to make GitHub the permanent source for PHP repositories going forward.
The attack arrived over the weekend, when two malicious commits were added to the php-src repository from the names of PHP developers Nikita Popov and Rasmus Lerdorf. The commits were disguised as minor typographical corrections that had to be fixed. However, closer analysis revealed their code was designed to install a backdoor for enabling remote code execution on a website running the infected version of PHP, according to Bleeping Computer.
In a blog post
published Sunday night, Popov says evidence indicates the PHP server had been compromised.
We dont yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account), he says.
While an investigation is still underway, Popov explains that we have decided that maintaining our own git infrastructure is an unnecessary security risk. As a result, they will be discontinuing the git.php.net server and all code changes should instead be directly pushed to GitHub. Write access to the PHP repositories was previously handled through a homegrown system called Karma, and the repositories on GitHub had been only mirrors; now, they will become canonical.
Were reviewing the repositories for any corruption beyond the two referenced commits, Popov says. 
Read more details
here
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Attackers Target PHP Git Server to Backdoor Source Code