MyBB Community Forums

Full Version: PHP.net compromised and used to attack visitors
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
If you have visited php.net from the 22nd to the 24th of October 2013 there is a small chance that your PC have been infected. Fortunately the PHP source code seams not be affected.

http://www.pcworld.com/article/2057980/p...itors.html
http://php.net/archive/2013.php#id2013-10-24-2
Is this issue already resolved?
Yes, they moved the affected websites to new servers.
Was it a JDB or iframe exploit or what? Really amazed to see such a big network getting compromised however its true that nothing is secure.
Ars has a decent writeup: http://arstechnica.com/security/2013/10/...h-malware/

Quote:Thursday's compromise caused some php.net visitors to download "Tepfer," a trojan spawned by the Magnitude Exploit Kit. [...] An analysis of the pcap file suggests the malware attack worked by exploiting a vulnerability in Adobe Flash, although it's possible that some victims were targeted by attacks that exploited Java, Internet Explorer
I visited it quite a number of times, however I have a Chrome script blocker. I don't believe I would have got infected.
How can I check if my computer got infected? As far as I remember I visted this them a copule of days ago
Run it with a good antivirus. Only about 5 of the major 47 (or whatever) picked up the relevant virus.
Kaspersky, NOD32...