PDA

View Full Version : Malicious PhpMyAdmin Served From SourceForge Mirror


sl4shd0t
09-26-2012, 04:06 PM
http://feedads.g.doubleclick.net/~at/P1pIbI2Acpwn_JiMYl2NBmMjgKM/0/di</img> (http://feedads.g.doubleclick.net/~at/P1pIbI2Acpwn_JiMYl2NBmMjgKM/0/da)
http://feedads.g.doubleclick.net/~at/P1pIbI2Acpwn_JiMYl2NBmMjgKM/1/di</img> (http://feedads.g.doubleclick.net/~at/P1pIbI2Acpwn_JiMYl2NBmMjgKM/1/da)
An anonymous reader writes with a bit of news about the compromised download of phpMyAdmin discovered on an sf.net mirror yesterday: "A malicious version of the open source Web-based MySQL database administration tool phpMyAdmin has been discovered on one of the official mirror sites of SourceForge, the popular online code repository for free and open source software. The file &mdash; phpMyAdmin-3.5.2.2-all-languages.zip &mdash; was modified to include a backdoor that allowed attackers to remotely execute PHP code on the server running the malicious version of phpMyAdmin."The Sourceforge weblog has details. Someone compromised a mirror (since removed from rotation of course) around September 22nd. Luckily, only around 400 people grabbed the file before someone caught it.http://a.fsdn.com/sd/twitter_icon_large.png (http://twitter.com/home?status=Malicious+PhpMyAdmin+Served+From+Sourc eForge+Mirror%3A+http%3A%2F%2Fbit.ly%2FSzzsDS)http ://a.fsdn.com/sd/facebook_icon_large.png (http://www.facebook.com/sharer.php?u=http%3A%2F%2Fdevelopers.slashdot.org% 2Fstory%2F12%2F09%2F26%2F1422218%2Fmalicious-phpmyadmin-served-from-sourceforge-mirror%3Futm_source%3Dslashdot%26utm_medium%3Dface book)http://www.gstatic.com/images/icons/gplus-16.png (http://plus.google.com/share?url=http://developers.slashdot.org/story/12/09/26/1422218/malicious-phpmyadmin-served-from-sourceforge-mirror?utm_source=slashdot&utm_medium=googleplus)

Read more of this story (http://developers.slashdot.org/story/12/09/26/1422218/malicious-phpmyadmin-served-from-sourceforge-mirror?utm_source=rss1.0moreanon&utm_medium=feed) at Slashdot.
http://feeds.feedburner.com/~r/Slashdot/slashdotDevelopers/~4/15L5Bg-UnmY

More... (http://rss.slashdot.org/~r/Slashdot/slashdotDevelopers/~3/15L5Bg-UnmY/malicious-phpmyadmin-served-from-sourceforge-mirror)