Forum Moderators: coopster

Message Too Old, No Replies

PHP wiki hacked .concerns for security of PHP source code

French company Vupen Security alerts to hack of PHP site

         

Leosghost

12:17 am on Mar 22, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



From Vupen Security via TheRegister comes the alert that a Chinese hacker exploited a vulnerability in the wiki and escalated it to gain account credentials that could allow access to the PHP repository ..the hacker also used a security flaw in linux in the attack.

Word of the attack began circulating on Friday on underground web forums monitored by researchers from France-based Vupen Security. Based on discussions that took place there, the compromise of wiki.php.net appears to have originated from a “Chinese hacker who exploited a vulnerability in the Wiki application (DokuWiki) installed on the server,”


The site has been down during investigation since Friday 18th March

“Our biggest concern is, of course, the integrity of our source code,” the maintainers wrote. “We did an extensive code audit and looked at every commit since 5.3.5 to make sure that no stolen accounts were used to inject anything malicious. Nothing was found.”

Story here [theregister.co.uk]

chrisranjana

6:54 am on Mar 22, 2011 (gmt 0)

10+ Year Member



Is it the main wiki website ?

coopster

9:59 pm on Mar 22, 2011 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



wiki.php.net

The story was posted on the PHP home page Saturday. The official PHP news release will be here for future reference ...
[php.net...]

g1smd

10:02 pm on Mar 22, 2011 (gmt 0)

coopster

10:15 pm on Mar 22, 2011 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



Flashback, Friday, December 24, 2010 ...

Its not a great feeling to have your account hacked into, but I do wonder what the intentions were.. Maybe just an credentials check, which was supposed to be followed by evil commits if noone had spotted the first one? The Chinese government trying to introduce security holes so they can break into PHP websites?
In any case. It took less then 10minutes for 3 people to catch it, that is pretty cool.


You gotta wonder if the crackers were challenged by that blog post last December from Hannes Magnusson [bjori.blogspot.com]?