News Feed
Jobs Feed
Sections




News Archive
Grzegorz Godlewski:
PHP.Kryptik.AB - Give me your FTP!
November 20, 2012 @ 14:14:04

Grzegorz Godlewski has written up a post about a piece of PHP-related malware that, if it gets into your application, can render your site inaccessible (not to mention blocked by Google's "safe browsing") - PHP.Kryptik.AB.

One could think a PHP Developer is free from viruses and malware - and be wrong. Meet PHP.Kryptik.AB - the PHP malware. If you already know this bastard - high five! But if you don't - be prepared! Basically the story starts from a standard computer trojan which (I suppose) attacks popular FTP clients that store FTP login credentials unencrypted. Then it sends fetched informations to a remote host which (by the cover of night) logs into the FTP servers and infects PHP base web-pages by injecting a piece of JavaScript code, that gets executed when a user enters a site.

He describes the injected code, what kind of files the malware looks for when it executes and how you can fix the problem if you've already been infected. There's also a bit about how you can prevent yourself from being infected (including the suggestion of using something like KeePass or 1Password to manage and create harder to crack passwords).

0 comments voice your opinion now!
malware javascript infect phpkryptikab ftp


blog comments powered by Disqus

Similar Posts

PHPBuilder.com: AJAX and PHP Part 4 - Forms and JavaScript Limitations

Jacques Marneweck's Blog: Smarty tip for including multiple javascript files

Paul James' Blog: HTTP Authentication with HTML Forms

Community News: jPOP Framework - Javascript & PHP

Vinu Thomas' Blog: PHPLiveX - Tutorial


Community Events











Don't see your event here?
Let us know!


rest conference database opinion testing zendframework2 podcast interview phpunit usergroup development introduction symfony2 google series community release functional framework language

All content copyright, 2013 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework