RE: [PHP] PHP.Pirus
| From: | Maxim Maletsky | Date: | Fri, 01 Dec 2000 02:11:22 +0000 |
| Subject: | RE: [PHP] PHP.Pirus | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-28147@lists.php.net to get a copy of this message | ||
the file MUST somehow be uploaded on your system, right?
then if you already got a chance to do so why not to write some bunch of
system functions, (including an email notification to know where, when and
who uploaded your virus) and then just get in there and crash it all. that's
a real virus. :-))))
BUT, in the name of god: the file is being uploaded by 'someone'! It doesn't
come from air.
MORAL: damages are inevitable if someone else has an access to your server.
A REAL VIRUS WOULD BE: Someone sends you an attachment and inside your qmail
(somehow again with the power of god) the file autoexecutes gaining the root
permissions, shutting down your whole network after what it deletes your
hard drives ...
Hard to imagine that it will ever happen.
Cheers,
Maxim Maletsky.
-----Original Message-----
From: Matt "TrollBoy" Wiseman [mailto:trollboy@defnet.com]
Sent: Friday, December 01, 2000 5:22 AM
To: Jason Lavigne; Rasmus Lerdorf
Cc: php-general@lists.php.net
Subject: Re: [PHP] PHP.Pirus
it wasn't so much a "Oh god watch out" type of e-mail, but mopre a look what
they've done now type of thing. To me this virus ranks right up there with
the php irc server I heard of a while back..
(accidently sent from my work account "Matt, Tech Support")
Matt "Trollboy" Wiseman
www.shoggoth.net/trollboy.jpg
Trollboy@shoggoth.net
"I wish the world had one throat!!"
-Al Bundy
----- Original Message -----
From: "Jason Lavigne" <jlavigne@stonecroft.net>
To: "Rasmus Lerdorf" <rasmus@php.net>
Cc: <php-general@lists.php.net>
Sent: Friday, December 01, 2000 3:08 AM
Subject: Re: [PHP] PHP.Pirus
> I think it is funny. It could make a mess of your system but it could also
> open you up to the world. As soon as you get "infected" you will no longer
> be in charge of your files. Sneaky.
>
> Anyways, like you said, this is one of those "You must infect yourself to
be
> infected" so not to worry.
>
> Jay
>
> ----- Original Message -----
> From: "Rasmus Lerdorf" <rasmus@php.net>
> To: "Matt, Tech Support" <mjw@defnet.com>
> Cc: <php-general@lists.php.net>; <phpslash-users@lists.sourceforge.net>
> Sent: Thursday, November 30, 2000 4:02 PM
> Subject: Re: [PHP] PHP.Pirus
>
>
> > This has been there for a while, and it is silly. If you are executing
> > random executables on your web server then you are in trouble anyway.
The
> > fact that this thing inserts some stuff into PHP files that might later
> > screw up your system is irrelevant. The executable that does this
> > insertion might as well go and do this same damage.
> >
> > -Rasmus
> >
> > On Thu, 30 Nov 2000, Matt, Tech Support wrote:
> >
> > > You knew it HAD to happen...
> > >
> > > http://www.sarc.com/avcenter/venc/data/php.pirus.htmlŠ
> > > ñöüYVÖ‡óvR•*
> > >
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net