svn: /web/php/trunk/archive/ archive.xml entries/2011-03-19-1.xml

From: Date: Sat, 19 Mar 2011 19:00:33 +0000
Subject: svn: /web/php/trunk/archive/ archive.xml entries/2011-03-19-1.xml
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-10657@lists.php.net to get a copy of this message
rasmus Sat, 19 Mar 2011 19:00:33 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=309449 Log: Security note Changed paths: U web/php/trunk/archive/archive.xml A web/php/trunk/archive/entries/2011-03-19-1.xml Modified: web/php/trunk/archive/archive.xml =================================================================== --- web/php/trunk/archive/archive.xml 2011-03-19 18:59:48 UTC (rev 309448) +++ web/php/trunk/archive/archive.xml 2011-03-19 19:00:33 UTC (rev 309449) @@ -9,6 +9,7 @@ <uri>http://php.net/contact</uri> <email>php-webmaster@lists.php.net</email> </author> + <xi:include href="entries/2011-03-19-1.xml"/> <xi:include href="entries/2011-03-17-1.xml"/> <xi:include href="entries/2011-03-03-1.xml"/> <xi:include href="entries/2011-01-06-1.xml"/> Added: web/php/trunk/archive/entries/2011-03-19-1.xml =================================================================== --- web/php/trunk/archive/entries/2011-03-19-1.xml (rev 0) +++ web/php/trunk/archive/entries/2011-03-19-1.xml 2011-03-19 19:00:33 UTC (rev 309449) @@ -0,0 +1,25 @@ +<?xml version="1.0" encoding="utf-8"?> +<entry xmlns="http://www.w3.org/2005/Atom"> + <title>php.net security notice</title> + <id>http://www.php.net/archive/2011.php#id2011-03-19-2</id> + <published>2011-03-19T11:20:04-07:00</published> + <updated>2011-03-19T11:20:04-07:00</updated> + <category term="frontpage" label="PHP.net frontpage news"/> + <link href="http://www.php.net/index.php#id2011-03-19-2" rel="alternate" type="text/html"/> + <link href="http://www.php.net/archive/2011.php#id2011-03-19-2" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"> + <p>The wiki.php.net box was compromised and the attackers were able to + collect wiki account credentials. No other machines in the php.net + infrastructure appear to have been affected. Our biggest concern is, + of course, the integrity of our source code. We did an extensive code + audit and looked at every commit since 5.3.5 to make sure that no stolen + accounts were used to inject anything malicious. Nothing was found. + The compromised machine has been wiped and we are forcing a password + change for all svn accounts.</p> + + <p>We are still investigating the details of the attack which combined a + vulnerability in the Wiki software with a Linux root exploit.</p> + </div> + </content> +</entry>

« previous php.webmaster (#10657) next »