RE: [PHP] PHP.Pirus

From: Date: Fri, 01 Dec 2000 02:11:22 +0000
Subject: RE: [PHP] PHP.Pirus
Groups: php.general 
Request: Send a blank email to php-general+get-28147@lists.php.net to get a copy of this message
the file MUST somehow be uploaded on your system, right? then if you already got a chance to do so why not to write some bunch of system functions, (including an email notification to know where, when and who uploaded your virus) and then just get in there and crash it all. that's a real virus. :-)))) BUT, in the name of god: the file is being uploaded by 'someone'! It doesn't come from air. MORAL: damages are inevitable if someone else has an access to your server. A REAL VIRUS WOULD BE: Someone sends you an attachment and inside your qmail (somehow again with the power of god) the file autoexecutes gaining the root permissions, shutting down your whole network after what it deletes your hard drives ... Hard to imagine that it will ever happen. Cheers, Maxim Maletsky. -----Original Message----- From: Matt "TrollBoy" Wiseman [mailto:trollboy@defnet.com] Sent: Friday, December 01, 2000 5:22 AM To: Jason Lavigne; Rasmus Lerdorf Cc: php-general@lists.php.net Subject: Re: [PHP] PHP.Pirus it wasn't so much a "Oh god watch out" type of e-mail, but mopre a look what they've done now type of thing. To me this virus ranks right up there with the php irc server I heard of a while back.. (accidently sent from my work account "Matt, Tech Support") Matt "Trollboy" Wiseman www.shoggoth.net/trollboy.jpg Trollboy@shoggoth.net "I wish the world had one throat!!" -Al Bundy ----- Original Message ----- From: "Jason Lavigne" <jlavigne@stonecroft.net> To: "Rasmus Lerdorf" <rasmus@php.net> Cc: <php-general@lists.php.net> Sent: Friday, December 01, 2000 3:08 AM Subject: Re: [PHP] PHP.Pirus > I think it is funny. It could make a mess of your system but it could also > open you up to the world. As soon as you get "infected" you will no longer > be in charge of your files. Sneaky. > > Anyways, like you said, this is one of those "You must infect yourself to be > infected" so not to worry. > > Jay > > ----- Original Message ----- > From: "Rasmus Lerdorf" <rasmus@php.net> > To: "Matt, Tech Support" <mjw@defnet.com> > Cc: <php-general@lists.php.net>; <phpslash-users@lists.sourceforge.net> > Sent: Thursday, November 30, 2000 4:02 PM > Subject: Re: [PHP] PHP.Pirus > > > > This has been there for a while, and it is silly. If you are executing > > random executables on your web server then you are in trouble anyway. The > > fact that this thing inserts some stuff into PHP files that might later > > screw up your system is irrelevant. The executable that does this > > insertion might as well go and do this same damage. > > > > -Rasmus > > > > On Thu, 30 Nov 2000, Matt, Tech Support wrote: > > > > > You knew it HAD to happen... > > > > > > http://www.sarc.com/avcenter/venc/data/php.pirus.htmlŠ > > > ñöüYVÖ‡óvR•* > > > > > > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#28147) next »