LWN.net Logo

Backdoor inserted into Piwik

Backdoor inserted into Piwik

Posted Nov 28, 2012 12:37 UTC (Wed) by njwhite (subscriber, #51848)
Parent article: Backdoor inserted into Piwik

Their advice to backup config.ini.php and then unpack a fresh install is sensible, but does point to an issue with having a config file be direct code; if they'd decided to add part of the backdoor to config.ini.php, restoring things could have got rather trickier.

Anyway, it's a good advisory, and it looks like they did a very good job of responding. The forum post linked to there has more details of what the backdoor does, for those interested: http://forum.piwik.org/read.php?2,97666


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds