Breach At PHP.net Causes Site To Serve Malware
Popular PHP.net developer site distributed malware after experiencing server security breaches
PHP.net, one of the Web's most popular application development sites, was breached last week, causing it to serve malware to a number of its users.
In a series of blogs issued Thursday, the operators of PHP.net disclosed that two of the site's servers had been compromised. The operators say they still don't know how the breach happened.
The blogs were posted shortly after researchers at Barracuda Labs, Google, AlienVault, and Websense reported JavaScript malware emanating from PHP.net Web servers. PHP.net says that the malware was served "to a small percentage of PHP.net users" from Oct. 22 to Oct. 24.
"All affected services have been migrated off those servers," PHP.net says in its latest blog. "We have verified that our Git repository was not compromised, and it remains in read only mode as services are brought back up in full.
"As it's possible that the attackers may have accessed the private key of the php.net SSL certificate, we have revoked it immediately," the blog says. The site has gotten a new certificate and has restored access to PHP.net sites that require SSL.
All PHP.net users will have their passwords reset in the next few days, the blog says. Users of PHP software "are unaffected by this: this is solely for people committing code to projects hosted on svn.php.net or git.php.net," the organization states.
Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
About the Author
You May Also Like