<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Thu, 23 May 2013 20:25:55 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[DevShed: Hackers Compromise PHP Sites to Launch Attacks]]></title>
      <guid>http://www.phpdeveloper.org/news/18911</guid>
      <link>http://www.phpdeveloper.org/news/18911</link>
      <description><![CDATA[<p>
According to <a href="http://www.devshed.com/c/a/PHP/Hackers-Compromise-PHP-Sites-to-Launch-Attacks-93656/">this new post</a> on DevShed, there have been several targeted attacks against U.S. bank websites (DDoS), some of which involved the compromise of PHP-based applications.
</p>
<blockquote>
Once the hackers got into the PHP-based websites, they inserted toolkits to turn them into launch pads for their distributed denial-of-service attacks. Hackers then launched the attacks on banks by connecting directly to the compromised PHP-based websites and sending them commands, or took advantage of intermediate servers, proxies or scripts to make the websites do their bidding. InformationWeek lists three attack tools used by the hackers: KamiKaze, AMOS, and the "itsokaynoproblembro" toolkit, also known as Brobot.
</blockquote>
<p>
Several major banks have been targeted including Bank of America, JP Morgan/Chase, HSBC and Well Fargo. The main problem was out-of-date software running on the site containing known security issues the attackers could exploit to install their own software.
</p>
<blockquote>
If a hacker can break into a PHP-based website to use it as a staging area for an attack on a different website, they can also use that website to store stolen information. InformationWeek cited the example of the Eurograbber attack campaign, revealed earlier this month. The gang involved in that campaign stole $47 million from more than 30,000 corporate and private banking customers - and used PHP-based websites into which they hacked to store stolen information.
</blockquote>]]></description>
      <pubDate>Tue, 18 Dec 2012 12:07:35 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: Ottawa Food Bank Improve Distribution Databases via PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/5447</guid>
      <link>http://www.phpdeveloper.org/news/5447</link>
      <description><![CDATA[<p>
Via <a href="http://www.php-mag.net/magphpde/magphpde_news/psecom,id,25832,nodeid,5.html>this post</a> from the PHP Magazine site today, we learn about how PHP (along side several other open source solutions) is helping to improve the distribution of food and resources at the Ottowa Food Bank.
</p>
<quote>
<i>
The first phase of FoodNet is to develop food ordering and information sharing systems so that a city-wide network of missions, food cupboards and other food distributors can better communicate with the food bank, said executive director Peter Tilley. In the second phase of the project, the Food Bank will work with the Social Planning Council of Ottawa on an agency boundary-mapping system and a rapid agency look-up utility.
</i>
</quote>
<p>
<a href="http://www.ottawabusinessjournal.com/293105797015163.php">The system</a> is being developed by the several groups, but they opted to go with a PHP/SQL database solution over any of their software ultimately.
</p>]]></description>
      <pubDate>Thu, 25 May 2006 10:48:35 -0500</pubDate>
    </item>
  </channel>
</rss>
