svn: /web/php/trunk/archive/ archive.xml entries/2011-03-19-1.xml
| From: | Rasmus Lerdorf | Date: | Sat, 19 Mar 2011 19:00:33 +0000 |
| Subject: | svn: /web/php/trunk/archive/ archive.xml entries/2011-03-19-1.xml | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-10657@lists.php.net to get a copy of this message | ||
rasmus Sat, 19 Mar 2011 19:00:33 +0000
Revision: http://svn.php.net/viewvc?view=revision&revision=309449
Log:
Security note
Changed paths:
U web/php/trunk/archive/archive.xml
A web/php/trunk/archive/entries/2011-03-19-1.xml
Modified: web/php/trunk/archive/archive.xml
===================================================================
--- web/php/trunk/archive/archive.xml 2011-03-19 18:59:48 UTC (rev 309448)
+++ web/php/trunk/archive/archive.xml 2011-03-19 19:00:33 UTC (rev 309449)
@@ -9,6 +9,7 @@
<uri>http://php.net/contact</uri>
<email>php-webmaster@lists.php.net</email>
</author>
+ <xi:include href="entries/2011-03-19-1.xml"/>
<xi:include href="entries/2011-03-17-1.xml"/>
<xi:include href="entries/2011-03-03-1.xml"/>
<xi:include href="entries/2011-01-06-1.xml"/>
Added: web/php/trunk/archive/entries/2011-03-19-1.xml
===================================================================
--- web/php/trunk/archive/entries/2011-03-19-1.xml (rev 0)
+++ web/php/trunk/archive/entries/2011-03-19-1.xml 2011-03-19 19:00:33 UTC (rev 309449)
@@ -0,0 +1,25 @@
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom">
+ <title>php.net security notice</title>
+ <id>http://www.php.net/archive/2011.php#id2011-03-19-2</id>
+ <published>2011-03-19T11:20:04-07:00</published>
+ <updated>2011-03-19T11:20:04-07:00</updated>
+ <category term="frontpage" label="PHP.net frontpage news"/>
+ <link href="http://www.php.net/index.php#id2011-03-19-2"
rel="alternate" type="text/html"/>
+ <link href="http://www.php.net/archive/2011.php#id2011-03-19-2"
rel="via" type="text/html"/>
+ <content type="xhtml">
+ <div xmlns="http://www.w3.org/1999/xhtml">
+ <p>The wiki.php.net box was compromised and the attackers were able to
+ collect wiki account credentials. No other machines in the php.net
+ infrastructure appear to have been affected. Our biggest concern is,
+ of course, the integrity of our source code. We did an extensive code
+ audit and looked at every commit since 5.3.5 to make sure that no stolen
+ accounts were used to inject anything malicious. Nothing was found.
+ The compromised machine has been wiped and we are forcing a password
+ change for all svn accounts.</p>
+
+ <p>We are still investigating the details of the attack which combined a
+ vulnerability in the Wiki software with a Linux root exploit.</p>
+ </div>
+ </content>
+</entry>