Re: Recent hack on bonsai.php.net
| From: | Rasmus Lerdorf | Date: | Thu, 01 Sep 2005 23:47:38 +0000 |
| Subject: | Re: Recent hack on bonsai.php.net | ||
| References: | 1 | Groups: | php.mirrors |
| Request: | Send a blank email to php-mirrors+get-29175@lists.php.net to get a copy of this message | ||
RG wrote:
> Dear PHP administrator,
> As you are probably aware, bonsai.php.net was currently compromised.
> The so called hacker that did this was leaked a CVS 0day (an
> unpublicized exploit). The two other people he worked with did not have
> the intention to bring bonsai.php.net down, they were only looking for
> bugs, I think one of them even submitted a bug report. However, the lone
> hacker, whose handle is pacifico thought it would be cool to deface to
> bonsai.php.net. After gaining access to the CVS he started boasting
> about backdooring PHP's source code, as well as php.net. He made his
> intentions clear, he wants to achieve as much fame as possible by
> backdooring and defacing php.net. He also claimed to have ftp, and ssh
> access to php.net. His IP is 24.163.93.176. I know all of this because
> he was chatting on my IRC server, so I have logs.
> If you have any further inquiries, you may contact me by replying or
> chatting me on AIM, my screenname is ScriptBlue.
> PS, I am revealing all of this information out of respect for such a
> great community of developers.
We are aware of it, thanks. The bonsai machine only holds a mirror of
the source repository, so there is no danger of any backdoors being
introduced. Anything changed in the source repository on that machine
would be overwritten on the next synch from the master repository.
-Rasmus