* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, April 7, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Howard Stern’s Former Assistant Exposes Hostile Work Environment and Fraudulent NDAs in Shocking Lawsuit

    Good Night John Boy Returns to Cleveland This May with an Exciting New Shots Bar!

    Renewing Our Commitment to Safer Gaming for All

    Sony Interactive Entertainment Broadens Its Future with Cinemersive Labs Acquisition

    Miami Worldcenter Retail and Entertainment District Undergoes Major Ownership Shakeup

    Caesars Entertainment launches inclusive summer package at 3 Las Vegas properties – FOX5 Vegas

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Amkor Technology to Reveal Exciting First Quarter 2026 Financial Results on April 27, 2026

    Unveiling the Most Exciting Technology Innovations at IMTS 2026

    Taiwan’s Daring Breakthrough in Defense Technology

    Chattahoochee Technical College Elevates Air Conditioning Program with Major YORK Equipment Donation

    How UT Tyler School of Medicine is Transforming Healthcare Training in East Texas with Cutting-Edge 3D Technology

    Forsyth County Deputies Use Cutting-Edge Tracking Technology to End High-Speed Chase with Juvenile Driver

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Howard Stern’s Former Assistant Exposes Hostile Work Environment and Fraudulent NDAs in Shocking Lawsuit

    Good Night John Boy Returns to Cleveland This May with an Exciting New Shots Bar!

    Renewing Our Commitment to Safer Gaming for All

    Sony Interactive Entertainment Broadens Its Future with Cinemersive Labs Acquisition

    Miami Worldcenter Retail and Entertainment District Undergoes Major Ownership Shakeup

    Caesars Entertainment launches inclusive summer package at 3 Las Vegas properties – FOX5 Vegas

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Amkor Technology to Reveal Exciting First Quarter 2026 Financial Results on April 27, 2026

    Unveiling the Most Exciting Technology Innovations at IMTS 2026

    Taiwan’s Daring Breakthrough in Defense Technology

    Chattahoochee Technical College Elevates Air Conditioning Program with Major YORK Equipment Donation

    How UT Tyler School of Medicine is Transforming Healthcare Training in East Texas with Cutting-Edge 3D Technology

    Forsyth County Deputies Use Cutting-Edge Tracking Technology to End High-Speed Chase with Juvenile Driver

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

June 7, 2024
in Technology
Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells
Share on FacebookShare on Twitter

HackerImage: Midjourney

Chinese threat actors are targeting ThinkPHP applications vulnerable to CVE-2018-20062 and CVE-2019-9082 to install a persistent web shell named Dama.

The web shell enables further exploitation of the breached endpoints, such as enlisting them as part of the attackers’ infrastructure to evade detection in subsequent operations.

The first signs of this activity date back to October 2023, but according to Akamai analysts monitoring it, the malicious activity has recently expanded and intensified.

Targeting old vulnerabilities

ThinkPHP is an open-source web application development framework that is particularly popular in China.

CVE-2018-20062, fixed in December 2018, is an issue discovered in NoneCMS 1.3, allowing remote attackers to execute arbitrary PHP code via crafted use of the filter parameter.

CVE-2019-9082 impacts ThinkPHP 3.2.4 and older, used in Open Source BMS 1.1.1., is a remote command execution problem addressed in February 2019.

The two flaws are leveraged in this campaign to enable the attackers to perform remote code execution, impacting the underlying content management systems (CMS) on the target endpoints.

Specifically, the attackers exploit the bugs to download a text file named “public.txt,” which, in reality, is the obfuscated Dama web shell saved as “roeter.php.”

The payload is downloaded from compromised servers located in Hong Kong and provides the attackers with remote server control following a simple authentication step using the password “admin.”

Akamai says the servers delivering the payloads are infected themselves with the same web shell, so it appears that compromised systems are turned into nodes in the attacker’s infrastructure.

The Dama web shell

Dama has advanced capabilities enabling the threat actors to navigate the file system on the compromised server, upload files, and gather system data, essentially aiding in privilege escalation.

It can also perform network port scanning, access databases, and bypass disabled PHP functions for shell command execution.

The Dama interfaceThe Dama interface
​​​​​​​Source: Akamai

A notable omission from Dama’s capabilities is the lack of a command-line interface, which would allow threat actors a more hands-on approach to executing commands.

Akamai notes that this missing functionality is notable given Dama’s otherwise extensive functionality.

Mitigation

Exploiting 6-year-old flaws serves as another reminder of the persistent problem of poor vulnerability management, as attackers, in this case, leverage security vulnerabilities patched a long time ago.

The recommended action for potentially impacted organizations is to move to the most recent ThinkPHP, version 8.0, which is safe against known remote code execution bugs.

Akamai also notes that the targeting scope of this campaign is broad, even impacting systems not using ThinkPHP, which suggests opportunistic motives.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-exploit-2018-thinkphp-flaws-to-install-dama-web-shells/

Tags: Exploithackerstechnology
Previous Post

Ukraine says hackers abuse SyncThing data sync tool to steal data

Next Post

Los Angeles Unified School District investigates data theft claims

Ecology Group Accelerates Growth with Strategic Acquisition of Leading Ecological Consultancy

April 7, 2026

Mississippi Sound Coalition Unveils Exciting New Science-Based Recommendations

April 7, 2026

Men vs. Women: Science Finally Reveals Who Has Worse Farts!

April 7, 2026

Asics Launches an Exciting New Sequel to Its Most Innovative Lifestyle Sneaker

April 7, 2026

Student Teams Unveil Groundbreaking Solutions to Real-World Challenges at Nexus Summit

April 7, 2026

Were Cockroaches the Only Intruders? Dimon Spots a Malodorous Mammal at the Economy’s Doorstep

April 7, 2026

Howard Stern’s Former Assistant Exposes Hostile Work Environment and Fraudulent NDAs in Shocking Lawsuit

April 7, 2026

US sexual health report card: High pleasure, low testing, stark gender disparities – Medical Xpress

April 7, 2026

Crucial Sales and Property Tax Issues Dominate Tuesday’s St. Louis Municipal Elections

April 7, 2026

Amkor Technology to Reveal Exciting First Quarter 2026 Financial Results on April 27, 2026

April 7, 2026

Categories

Archives

April 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
27282930  
« Mar    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,158)
  • Economy (1,176)
  • Entertainment (22,052)
  • General (20,846)
  • Health (10,212)
  • Lifestyle (1,190)
  • News (22,149)
  • People (1,178)
  • Politics (1,194)
  • Science (16,391)
  • Sports (21,676)
  • Technology (16,158)
  • World (1,168)

Recent News

Ecology Group Accelerates Growth with Strategic Acquisition of Leading Ecological Consultancy

April 7, 2026

Mississippi Sound Coalition Unveils Exciting New Science-Based Recommendations

April 7, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version