原文:
The wiki.php.net boxwas compromised and the attackers were able to collect wiki account credentials. No other machines in the php.net infrastructure appear to have been affected. Our biggest concern is, of course, the integrity of our source code. We did an extensive code audit and looked at EVEry commit since 5.3.5 to make sure that no stolen accounts were used to inject anything malicious. Nothing was found. The compromised machine has been wiped and we are forcing a password change for all svn accounts.
We are still investigating the details of the attack which combined a vulnerability in the Wiki software with a Linux root exploit.
内容大致是:
由于wiki账号被盗,PHP的代码源极有可能被污染,当然,PHP团队已经做最大的努力以保证自PHP5.3.5版本的代码没有收到污染,并且强迫SVN修改现有的密码。
而事件目前的状态是,他们仍然没法锁定漏洞所在,因为他们仍在排查。
一个很明显的问题是,PHP5.3.6以及其后续版本的代码已经被污染,目前只能把未受污染的代码版本确保到PHP5.3.5,下载PHP代码的人,要小心了。
而windows.php.net和wiki.php.net也已经暂停访问。
网吧网管、收银故事大全 | 2010年网吧网管工具大全 | Ghost网克教程 | 网管教程 | 网吧母盘教程2010 |鬼影病毒爆发,你准备好了吗? | 万象皮肤大全下载 | PUBWIN讨论 | 迅闪2009 | 网吧虚拟磁盘 | 网吧/网管呼叫工具 | 网吧易语言源码2010第一版| 网吧网管心银心情故事 | 网吧公告程序大全 |网吧远程工具 | 最新收集实用贴!| 网吧精品软件,只提供网吧软件!| 免费无盘游戏菜单 |Win2008专门讨论及下载