* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, July 20, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Canes owner Tom Dundon’s real estate firm eyes entertainment complex near RDU – The Business Journals

    Canes Owner Tom Dundon’s Real Estate Firm Unveils Plans for Thrilling New Entertainment Complex Near RDU

    Inspired Entertainment, Inc.’s (NASDAQ:INSE) Price Is Right But Growth Is Lacking After Shares Rocket 29% – simplywall.st

    Inspired Entertainment Soars 29% but Growth Momentum Falls Short

    Kroger shares summer entertainment tips – Supermarket Perimeter

    Ultimate Summer Entertainment Tips to Make Your Season Unforgettable

    Theater at Santa Fe’s San Isidro Plaza will be converted into IMAX, family entertainment venue – Santa Fe New Mexican

    Santa Fe’s San Isidro Plaza Theater Transforms into Exciting IMAX Family Entertainment Venue

    B&B Theatres will open massive entertainment complex in Texas – The Business Journals

    B&B Theatres will open massive entertainment complex in Texas – The Business Journals

    Rough times for broadcast networks illustrate changing media landscape – New Haven Register

    Broadcast Networks Confront Turbulent Times in a Rapidly Changing Media Landscape

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    BlackSky Technology Inc. Stock Analysis and Forecast – Explosive wealth accumulation – Jammu Links News

    BlackSky Technology Inc.: Unlocking Explosive Wealth Potential Through Expert Stock Analysis and Forecast

    Polypurine Hairpin Technology is Safe, Effective at Inhibiting PCSK9 to Regulate Cholesterol – Pharmacy Times

    Polypurine Hairpin Technology: A Safe and Powerful Breakthrough for Controlling Cholesterol by Targeting PCSK9

    A major AI training data set contains millions of examples of personal data – MIT Technology Review

    A major AI training data set contains millions of examples of personal data – MIT Technology Review

    Simpson College to purchase medical simulation technology with grant funds – Iowa Capital Dispatch

    Simpson College to purchase medical simulation technology with grant funds – Iowa Capital Dispatch

    SailGP Technologies officially launches new center of excellence in technology & innovation – Sail-World.com

    SailGP Technologies officially launches new center of excellence in technology & innovation – Sail-World.com

    Victorville’s new gunfire-detecting technology already making strides, city says – NBC Los Angeles

    Victorville’s New Gunfire-Detecting Technology Is Already Making a Difference, City Officials Say

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Canes owner Tom Dundon’s real estate firm eyes entertainment complex near RDU – The Business Journals

    Canes Owner Tom Dundon’s Real Estate Firm Unveils Plans for Thrilling New Entertainment Complex Near RDU

    Inspired Entertainment, Inc.’s (NASDAQ:INSE) Price Is Right But Growth Is Lacking After Shares Rocket 29% – simplywall.st

    Inspired Entertainment Soars 29% but Growth Momentum Falls Short

    Kroger shares summer entertainment tips – Supermarket Perimeter

    Ultimate Summer Entertainment Tips to Make Your Season Unforgettable

    Theater at Santa Fe’s San Isidro Plaza will be converted into IMAX, family entertainment venue – Santa Fe New Mexican

    Santa Fe’s San Isidro Plaza Theater Transforms into Exciting IMAX Family Entertainment Venue

    B&B Theatres will open massive entertainment complex in Texas – The Business Journals

    B&B Theatres will open massive entertainment complex in Texas – The Business Journals

    Rough times for broadcast networks illustrate changing media landscape – New Haven Register

    Broadcast Networks Confront Turbulent Times in a Rapidly Changing Media Landscape

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    BlackSky Technology Inc. Stock Analysis and Forecast – Explosive wealth accumulation – Jammu Links News

    BlackSky Technology Inc.: Unlocking Explosive Wealth Potential Through Expert Stock Analysis and Forecast

    Polypurine Hairpin Technology is Safe, Effective at Inhibiting PCSK9 to Regulate Cholesterol – Pharmacy Times

    Polypurine Hairpin Technology: A Safe and Powerful Breakthrough for Controlling Cholesterol by Targeting PCSK9

    A major AI training data set contains millions of examples of personal data – MIT Technology Review

    A major AI training data set contains millions of examples of personal data – MIT Technology Review

    Simpson College to purchase medical simulation technology with grant funds – Iowa Capital Dispatch

    Simpson College to purchase medical simulation technology with grant funds – Iowa Capital Dispatch

    SailGP Technologies officially launches new center of excellence in technology & innovation – Sail-World.com

    SailGP Technologies officially launches new center of excellence in technology & innovation – Sail-World.com

    Victorville’s new gunfire-detecting technology already making strides, city says – NBC Los Angeles

    Victorville’s New Gunfire-Detecting Technology Is Already Making a Difference, City Officials Say

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

June 7, 2024
in Technology
Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells
Share on FacebookShare on Twitter

HackerImage: Midjourney

Chinese threat actors are targeting ThinkPHP applications vulnerable to CVE-2018-20062 and CVE-2019-9082 to install a persistent web shell named Dama.

The web shell enables further exploitation of the breached endpoints, such as enlisting them as part of the attackers’ infrastructure to evade detection in subsequent operations.

The first signs of this activity date back to October 2023, but according to Akamai analysts monitoring it, the malicious activity has recently expanded and intensified.

Targeting old vulnerabilities

ThinkPHP is an open-source web application development framework that is particularly popular in China.

CVE-2018-20062, fixed in December 2018, is an issue discovered in NoneCMS 1.3, allowing remote attackers to execute arbitrary PHP code via crafted use of the filter parameter.

CVE-2019-9082 impacts ThinkPHP 3.2.4 and older, used in Open Source BMS 1.1.1., is a remote command execution problem addressed in February 2019.

The two flaws are leveraged in this campaign to enable the attackers to perform remote code execution, impacting the underlying content management systems (CMS) on the target endpoints.

Specifically, the attackers exploit the bugs to download a text file named “public.txt,” which, in reality, is the obfuscated Dama web shell saved as “roeter.php.”

The payload is downloaded from compromised servers located in Hong Kong and provides the attackers with remote server control following a simple authentication step using the password “admin.”

Akamai says the servers delivering the payloads are infected themselves with the same web shell, so it appears that compromised systems are turned into nodes in the attacker’s infrastructure.

The Dama web shell

Dama has advanced capabilities enabling the threat actors to navigate the file system on the compromised server, upload files, and gather system data, essentially aiding in privilege escalation.

It can also perform network port scanning, access databases, and bypass disabled PHP functions for shell command execution.

The Dama interfaceThe Dama interface
​​​​​​​Source: Akamai

A notable omission from Dama’s capabilities is the lack of a command-line interface, which would allow threat actors a more hands-on approach to executing commands.

Akamai notes that this missing functionality is notable given Dama’s otherwise extensive functionality.

Mitigation

Exploiting 6-year-old flaws serves as another reminder of the persistent problem of poor vulnerability management, as attackers, in this case, leverage security vulnerabilities patched a long time ago.

The recommended action for potentially impacted organizations is to move to the most recent ThinkPHP, version 8.0, which is safe against known remote code execution bugs.

Akamai also notes that the targeting scope of this campaign is broad, even impacting systems not using ThinkPHP, which suggests opportunistic motives.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-exploit-2018-thinkphp-flaws-to-install-dama-web-shells/

Tags: Exploithackerstechnology
Previous Post

Ukraine says hackers abuse SyncThing data sync tool to steal data

Next Post

Los Angeles Unified School District investigates data theft claims

The kitchen sink has been thrown at the economy. Here’s why it’s not causing a recession. – MarketWatch

The kitchen sink has been thrown at the economy. Here’s why it’s not causing a recession. – MarketWatch

July 20, 2025
Canes owner Tom Dundon’s real estate firm eyes entertainment complex near RDU – The Business Journals

Canes Owner Tom Dundon’s Real Estate Firm Unveils Plans for Thrilling New Entertainment Complex Near RDU

July 20, 2025
Your health insurance premiums could soon go up 15 percent — or more – vox.com

Brace Yourself: Health Insurance Premiums Could Soar by 15%

July 20, 2025
Why Donald Trump is facing doubts in the ‘manosphere’ – CNN

Why Donald Trump Is Losing Support in the ‘Manosphere

July 20, 2025
BlackSky Technology Inc. Stock Analysis and Forecast – Explosive wealth accumulation – Jammu Links News

BlackSky Technology Inc.: Unlocking Explosive Wealth Potential Through Expert Stock Analysis and Forecast

July 20, 2025
Midsummer Classic peaks at 8.1 million views, the most watched All-Star Game in sports – MLB.com

Midsummer Classic peaks at 8.1 million views, the most watched All-Star Game in sports – MLB.com

July 20, 2025
Raleigh Launches After School Ecology Program for Middle and High School Students – Hoodline

Raleigh Launches Exciting New After-School Ecology Program for Teens

July 19, 2025
Mad Science: Acid-base reactions – FOX 7 Austin

Unleashing the Power of Acid-Base Reactions: A Thrilling Mad Science Adventure

July 19, 2025
A child’s biological sex may not always be a random 50-50 chance – Science News

Unexpected Discoveries Show That a Child’s Biological Sex Isn’t Always a Simple 50-50 Gamble

July 19, 2025
10 New Lifestyle Sneakers That Define 2025 – hypebeast.com

10 Must-Have Lifestyle Sneakers That Will Define 2025

July 19, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (729)
  • Economy (753)
  • Entertainment (21,638)
  • General (15,996)
  • Health (9,791)
  • Lifestyle (760)
  • News (22,149)
  • People (754)
  • Politics (762)
  • Science (15,969)
  • Sports (21,250)
  • Technology (15,735)
  • World (736)

Recent News

The kitchen sink has been thrown at the economy. Here’s why it’s not causing a recession. – MarketWatch

The kitchen sink has been thrown at the economy. Here’s why it’s not causing a recession. – MarketWatch

July 20, 2025
Canes owner Tom Dundon’s real estate firm eyes entertainment complex near RDU – The Business Journals

Canes Owner Tom Dundon’s Real Estate Firm Unveils Plans for Thrilling New Entertainment Complex Near RDU

July 20, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version