* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, May 14, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

    Paranovus Entertainment Technology Ltd. Unveils Exciting New Foreign Issuer Report

    TribeVibe Entertainment Triumphs at WOW Awards 2026 with Five Major Wins, Cementing Its Status as a Leader in India’s Live Entertainment Scene

    Sigourney Weaver Honored with Prestigious Award

    Dan Bucatinsky Opens Up About the Powerful, Emotional Final Scene with Lisa Kudrow in ‘The Comeback

    Lorraine Kelly Reveals Why Becoming a Grandmother Is the Greatest Joy of Her Life

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Revolutionizing Otologic Surgery: The Rise of Exoscope Technology at UHealth

    How Cutting-Edge AI Technologies Are Transforming the Future of Finance

    Lower Merion School District proposes new technology policy – PHL17.com

    WM Technology, Inc. Delivers Impressive First Quarter 2026 Results

    Medical Care Technologies Inc. (OTC Pink:MDCE) Expands AI Commercialization Strategy with Enterprise Vision Solutions – Yahoo Finance

    Has Silicon Motion Technology’s Stock Soared Too Far After a Stunning 368% Rally?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

    Paranovus Entertainment Technology Ltd. Unveils Exciting New Foreign Issuer Report

    TribeVibe Entertainment Triumphs at WOW Awards 2026 with Five Major Wins, Cementing Its Status as a Leader in India’s Live Entertainment Scene

    Sigourney Weaver Honored with Prestigious Award

    Dan Bucatinsky Opens Up About the Powerful, Emotional Final Scene with Lisa Kudrow in ‘The Comeback

    Lorraine Kelly Reveals Why Becoming a Grandmother Is the Greatest Joy of Her Life

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Revolutionizing Otologic Surgery: The Rise of Exoscope Technology at UHealth

    How Cutting-Edge AI Technologies Are Transforming the Future of Finance

    Lower Merion School District proposes new technology policy – PHL17.com

    WM Technology, Inc. Delivers Impressive First Quarter 2026 Results

    Medical Care Technologies Inc. (OTC Pink:MDCE) Expands AI Commercialization Strategy with Enterprise Vision Solutions – Yahoo Finance

    Has Silicon Motion Technology’s Stock Soared Too Far After a Stunning 368% Rally?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

June 7, 2024
in Technology
Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells
Share on FacebookShare on Twitter

HackerImage: Midjourney

Chinese threat actors are targeting ThinkPHP applications vulnerable to CVE-2018-20062 and CVE-2019-9082 to install a persistent web shell named Dama.

The web shell enables further exploitation of the breached endpoints, such as enlisting them as part of the attackers’ infrastructure to evade detection in subsequent operations.

The first signs of this activity date back to October 2023, but according to Akamai analysts monitoring it, the malicious activity has recently expanded and intensified.

Targeting old vulnerabilities

ThinkPHP is an open-source web application development framework that is particularly popular in China.

CVE-2018-20062, fixed in December 2018, is an issue discovered in NoneCMS 1.3, allowing remote attackers to execute arbitrary PHP code via crafted use of the filter parameter.

CVE-2019-9082 impacts ThinkPHP 3.2.4 and older, used in Open Source BMS 1.1.1., is a remote command execution problem addressed in February 2019.

The two flaws are leveraged in this campaign to enable the attackers to perform remote code execution, impacting the underlying content management systems (CMS) on the target endpoints.

Specifically, the attackers exploit the bugs to download a text file named “public.txt,” which, in reality, is the obfuscated Dama web shell saved as “roeter.php.”

The payload is downloaded from compromised servers located in Hong Kong and provides the attackers with remote server control following a simple authentication step using the password “admin.”

Akamai says the servers delivering the payloads are infected themselves with the same web shell, so it appears that compromised systems are turned into nodes in the attacker’s infrastructure.

The Dama web shell

Dama has advanced capabilities enabling the threat actors to navigate the file system on the compromised server, upload files, and gather system data, essentially aiding in privilege escalation.

It can also perform network port scanning, access databases, and bypass disabled PHP functions for shell command execution.

The Dama interfaceThe Dama interface
​​​​​​​Source: Akamai

A notable omission from Dama’s capabilities is the lack of a command-line interface, which would allow threat actors a more hands-on approach to executing commands.

Akamai notes that this missing functionality is notable given Dama’s otherwise extensive functionality.

Mitigation

Exploiting 6-year-old flaws serves as another reminder of the persistent problem of poor vulnerability management, as attackers, in this case, leverage security vulnerabilities patched a long time ago.

The recommended action for potentially impacted organizations is to move to the most recent ThinkPHP, version 8.0, which is safe against known remote code execution bugs.

Akamai also notes that the targeting scope of this campaign is broad, even impacting systems not using ThinkPHP, which suggests opportunistic motives.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-exploit-2018-thinkphp-flaws-to-install-dama-web-shells/

Tags: Exploithackerstechnology
Previous Post

Ukraine says hackers abuse SyncThing data sync tool to steal data

Next Post

Los Angeles Unified School District investigates data theft claims

OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

May 14, 2026

What’s in the billion-dollar paragraph behind the White House ballroom debate – PBS

May 13, 2026

Revolutionizing Otologic Surgery: The Rise of Exoscope Technology at UHealth

May 13, 2026

Broncos Dominate with 8 Exciting Nominations at Hashtag Sports Awards

May 13, 2026

Ecology Action Center names McLean Co. Green Award recipients – The Pantagraph

May 13, 2026

Quantum Breakthrough Poised to Transform Teleportation and Computing Forever

May 13, 2026

How Citizen Scientists Nearly Doubled the Known Brown Dwarf Count

May 13, 2026

Remington Hospitality Launches Chic ONE|GT Lifestyle Hotel in Grand Cayman

May 13, 2026

Foreigners with World Cup tickets won’t have to pay bonds to enter US, Trump administration tells AP – WRAL

May 13, 2026

Economy Faces a Troubling Downturn: What You Need to Know

May 13, 2026

Categories

Archives

May 2026
M T W T F S S
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,213)
  • Economy (1,234)
  • Entertainment (22,112)
  • General (21,496)
  • Health (10,267)
  • Lifestyle (1,246)
  • News (22,149)
  • People (1,235)
  • Politics (1,255)
  • Science (16,449)
  • Sports (21,732)
  • Technology (16,219)
  • World (1,225)

Recent News

OU and City Officials Celebrate Groundbreaking of Exciting New Rock Creek Entertainment District

May 14, 2026

What’s in the billion-dollar paragraph behind the White House ballroom debate – PBS

May 13, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version