Breach At PHP.net Causes Site To Serve Malware

  /     /     /  
Publicated : 22/11/2024   Category : security


Breach At PHP.net Causes Site To Serve Malware


Popular PHP.net developer site distributed malware after experiencing server security breaches



PHP.net, one of the Webs most popular application development sites, was breached last week, causing it to serve malware to a number of its users.
In a
series of blogs issued Thursday
, the operators of PHP.net disclosed that two of the sites servers had been compromised. The operators say they still dont know how the breach happened.
The blogs were posted shortly after researchers at
Barracuda Labs
, Google, AlienVault, and
Websense
reported JavaScript malware emanating from PHP.net Web servers. PHP.net says that the malware was served to a small percentage of PHP.net users from Oct. 22 to Oct. 24.
All affected services have been migrated off those servers, PHP.net says in its latest blog. We have verified that our Git repository was not compromised, and it remains in read only mode as services are brought back up in full.
As its possible that the attackers may have accessed the private key of the php.net SSL certificate, we have revoked it immediately, the blog says. The site has gotten a new certificate and has restored access to PHP.net sites that require SSL.
All PHP.net users will have their passwords reset in the next few days, the blog says. Users of PHP software are unaffected by this: this is solely for people committing code to projects hosted on svn.php.net or git.php.net, the organization states.
Have a comment on this story? Please click Add a Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Breach At PHP.net Causes Site To Serve Malware