Malicious changes have been identified in the Git repository of the PHP project

The PHP project developers have issued a warning about the compromise of the project's Git repository and the discovery of two malicious commits that were added on March 28 to the php-src repository under the names of Rasmus Lerdorf, the founder of PHP, and Nikita Popov, one of the key PHP developers.

As there is no confidence in the reliability of the server that hosted the Git repository, the developers decided that maintaining their own Git infrastructure poses additional security risks and have moved the reference repository to the GitHub platform, which is recommended to be used as the primary one. All changes should now be sent to GitHub, not git.php.net, and even development can now utilize the GitHub web interface.

In the first malicious commit, disguised as a typo fix in the file ext/zlib/zlib.c, a change was made that executes PHP code passed in the HTTP User Agent header if the content begins with the word 'zerodium'. After the developers noticed the malicious change and reverted it, a second commit appeared in the repository that overrode the developers' action and reinstated the malicious change.

The added code contains the line 'REMOVETHIS: sold to zerodium, mid 2017', which may hint that since 2017 there has been another, more stealthily camouflaged malicious change in the code, or an unpatched vulnerability sold to Zerodium, a company that purchases 0-day vulnerabilities (Zerodium has stated that it did not purchase information about vulnerabilities in PHP).

Currently, there is no detailed information regarding the incident; it is only assumed that the changes were added as a result of the hacking of git.php.net rather than the compromise of individual developers' accounts. An analysis of the repository for other malicious changes beyond the identified issues has begun. Everyone is invited to participate in the review, and any suspicious changes should be reported to security@php.net. server git.php.net, rather than compromising individual developer accounts. An analysis of the repository has begun to look for other malicious changes beyond the identified issues. Everyone is invited to review, and if any suspicious changes are detected, please report them to security@php.net.

Regarding the transition to GitHub, in order to gain write access to the new repository, development participants must join the PHP organization. Those who are not part of the PHP developers on GitHub should contact Nikita Popov at email nikic@php.net. A mandatory requirement for addition is the activation of two-factor authentication. After obtaining the proper rights, changing the repository can be accomplished by executing the command "git remote set-url origin git@github.com:php/php-src.git." Additionally, there is a discussion about making digital signatures for commits mandatory. It is also suggested to prohibit direct changes that have not undergone prior review.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster