自拍偷在线精品自拍偷,亚洲欧美中文日韩v在线观看不卡

發(fā)現(xiàn)wiki.php.net漏洞 PHP代碼源被黑

安全
源頭在于wiki.php.net的漏洞導(dǎo)致wiki賬號被盜,而wiki的賬號和php代碼源的SVN提交權(quán)限相關(guān)聯(lián)。

源頭在于wiki.php.net的漏洞導(dǎo)致wiki賬號被盜,而wiki的賬號和php代碼源的SVN提交權(quán)限相關(guān)聯(lián)。

有圖有真相:

原文:

The wiki.php.net boxwas compromised and the attackers were able to collect wiki account credentials. No other machines in the php.net infrastructure appear to have been affected. Our biggest concern is, of course, the integrity of our source code. We did an extensive code audit and looked at every commit since 5.3.5 to make sure that no stolen accounts were used to inject anything malicious. Nothing was found. The compromised machine has been wiped and we are forcing a password change for all svn accounts.

We are still investigating the details of the attack which combined a vulnerability in the Wiki software with a Linux root exploit.

內(nèi)容大致是:

由于wiki賬號被盜,PHP的代碼源極有可能被污染,當(dāng)然,PHP團隊已經(jīng)做最大的努力以保證自PHP5.3.5版本的代碼沒有收到污染,并且強迫SVN修改現(xiàn)有的密碼。

而事件目前的狀態(tài)是,他們?nèi)匀粵]法鎖定漏洞所在,因為他們?nèi)栽谂挪椤?/p>

一個很明顯的問題是,PHP5.3.6以及其后續(xù)版本的代碼已經(jīng)被污染,目前只能把未受污染的代碼版本確保到PHP5.3.5,下載PHP代碼的人,要小心了。

而windows.php.net和wiki.php.net也已經(jīng)暫停訪問。

文章來源:http://www.cnbeta.com/articles/138261.htm

責(zé)任編輯:佟健 來源: cnBeta
相關(guān)推薦

2011-03-25 08:35:55

2013-03-25 11:51:42

php漏洞代碼審計php

2012-02-06 09:14:26

2013-07-03 11:28:47

2014-07-03 09:58:07

2009-11-22 15:28:35

2011-06-15 16:58:26

PHP

2012-12-19 10:36:06

2012-04-12 16:05:50

2017-09-19 15:01:06

PHP漏洞滲透測試

2009-08-15 10:19:01

漏洞利用php expEXP程序

2015-02-04 14:50:29

2018-02-02 14:29:25

PHP漏洞服務(wù)器

2012-04-12 11:28:04

2020-12-18 09:40:30

應(yīng)用程序安全代碼

2009-07-28 15:04:34

PHP ASP.NET

2009-12-29 14:25:14

phpXSS漏洞

2012-04-12 15:42:35

2018-04-22 00:04:04

PHP C 代碼數(shù)據(jù)

2010-07-17 00:55:48

PHP Telnet
點贊
收藏

51CTO技術(shù)棧公眾號