Back to the feed

~/article/f5-big-ip-apm-malware-injects-a-php-web-shell-into-memory-evading-disk-s-1bvxy2
infoSource: The Hacker News

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Topics

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/f5-big-ip-apm-malware-injects-a-php-web-shell-into-memory-evading-disk-s-1bvxy2