3 ms·
Sorry, I'm not sure what you mean. The commit was almost certainly never meant to make it in to some server log, it was meant to be seen, and it was. In that wa
by kenmacd 6y ago
Sorry, I'm not sure what you mean. The commit was almost certainly never meant to make it in to some server log, it was meant to be seen, and it was. In that way it 'burned' (ie destroyed) the backdoor in to the PHP code repo.
And PHP does seem to care about the real exploit, the one in their infrastructure, which is why they're moving to Github.
Mind expanding on your above comment to help me understand?
- The_rationalist 6y agoMeant to be seen with a commit named "fix typo" wtf are you talking about? It's only due to luck that it has been reverted quick enough before being available through binaries.
- insomniacity 6y agoI mean exactly what you did - "The vulnerability that is of interest is the one that allowed these commits to be injected". Yes, it will be evident that the commits appeared in the git history, but not necessarily how they got there. If the git repo on disk suddenly has that commit, and no other usual indicators of compromise, that doesn't really give you anywhere to start looking for, what we agree is, the interesting vulnerability. All you have is "we know this box/service was definitely rooted, so look at all our infrastructure end-to-end". They care about the exploit enough to move - of course. But do they care enough to investigate and find the actual exploit? Or hand over the server image to someone who does? Unless they've wrapped it in some PHP, it's probably not their core competency. I don't follow the PHP project, so I don't know the answer to that.
- kenmacd 6y agoOkay, I see what you mean. I guess I assumed they wouldn't just accept that their server was hacked and not do a through investigation (or have someone do so), but I suppose that's mostly because I couldn't imagine not if it was me.
- Sebb767 6y ago> it was meant to be seen, and it was Are you sure about that? If anyone wanted to demonstrate their access/power, they would probably leave some way to identify themself as the author - with a half-hearted concealment like this, anyone could claim to have been the hacker. The only way this discovery would help the hacker, is if they intended to force a security audit of the karma system and/or the move to GitHub.
- kenmacd 6y ago> The only way this discovery would help the hacker, is if they intended to force a security audit of the karma system and/or the move to GitHub. I agree. Of course I can't be sure of anything here, but to me this commit seems suggestive that there's other injected code somewhere since mid 2017. You also make a good point on attribution. I had considered that too and if not wanting to take credit could tell us anything about the author. For example say you were an intelligence agency that knew about this access and knew it was being used by an enemy. Perhaps you couldn't let php know about the vulnerability without exposing that you had access to other data allowing you to know about it. Creating this commit could be a way to share knowledge without it being known where/how it was found. Of course that's all wild speculation.