ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Backdoor Added - But Found - in PHP

highMalwareimportance 42
Full article105 words · extracted from schneier.com · click to collapse

Unknown hackers attempted to add a backdoor to the PHP source code. It was two malicious commits, with the subject “fix typo” and the names of known PHP developers and maintainers. They were discovered and removed before being pushed out to any users. But since 79% of the Internet’s websites use PHP, it’s scary.

Developers have moved PHP to GitHub, which has better authentication. Hopefully it will be enough—PHP is a juicy target.

Tags: authentication, backdoors, hacking, open source, supply chain

Posted on April 9, 2021 at 8:54 AM17 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/04/backdoor-added-but-found-in-php.html