Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

[We] use bad software and bad machines for the wrong things. -- R. W. Hamming


devel / comp.lang.php / Re: go-pear backdoored

SubjectAuthor
o Re: go-pear backdooredMi Na

1
Re: go-pear backdoored

<c11e41bc-9063-4dd6-a5af-c55501ccec08n@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=309&group=comp.lang.php#309

  copy link   Newsgroups: comp.lang.php
X-Received: by 2002:a05:620a:1465:: with SMTP id j5mr8296712qkl.63.1627113790543;
Sat, 24 Jul 2021 01:03:10 -0700 (PDT)
X-Received: by 2002:a25:aa2b:: with SMTP id s40mr12103658ybi.103.1627113790217;
Sat, 24 Jul 2021 01:03:10 -0700 (PDT)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.snarked.org!Xbb.tags.giganews.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.lang.php
Date: Sat, 24 Jul 2021 01:03:10 -0700 (PDT)
In-Reply-To: <eli$1901231722@qaz.wtf>
Injection-Info: google-groups.googlegroups.com; posting-host=193.40.120.146; posting-account=s3OxiwkAAABE2kqiXXKi7ZVC4Hsq_zQz
NNTP-Posting-Host: 193.40.120.146
References: <eli$1901231722@qaz.wtf>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <c11e41bc-9063-4dd6-a5af-c55501ccec08n@googlegroups.com>
Subject: Re: go-pear backdoored
From: ya12983@mail.com (Mi Na)
Injection-Date: Sat, 24 Jul 2021 08:03:10 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: base64
Lines: 85
 by: Mi Na - Sat, 24 Jul 2021 08:03 UTC

Eli the Bearded kirjutas neljapΓ€ev, 24. jaanuar 2019 kl 00:24:02 UTC+2:
> `go-pear` goes _go pear-shaped_.
>
> https://arstechnica.com/information-technology/2019/01/pear-php-site-breach-lets-hackers-slip-malware-into-official-download/
>
> "If you have downloaded this go-pear.phar [package manager] in the
> past six months, you should get a new copy of the same release
> version from GitHub (pear/pearweb_phars) and compare file hashes,"
> officials wrote on the site's blog. "If different, you may have the
> infected file."
>
> The officials didn't say when the hack of their Web server occurred
> or precisely what the malicious version of go-pear.phar did to
> infected systems. Initial indications, however, look serious. For
> starters, the advice applies to anyone who has downloaded the
> package manager in the past six months. That suggests the hack may
> have occurred in the timeframe of last July, and no one noticed
> either it or the tainted download until this week.
>
> What's more, results from VirusTotal, the Google-owned malware
> scanning service, suggest that the malicious PEAR download
> installed a backdoor, possibly in the form of a Web shell, on
> infected servers.
>
> Elijah
> ------
> is no longer an active PHP user

πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ
πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ πŸ–οΈ

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor