PHP code injection Windows+Linux RCE

Bitcoin wallet Electrum now supports Lightning online payments, according to Coindesk on July 11. It has previously been reported that Bitcoin Wallet Electrum has released a beta version of Electrum 4.0, adding support for the Bitcoin Lightning Network.

There were five ransomware-related security incidents in November, including several new types of ransomware, such as NextCry ransomware, which attempted to attack Linux servers with a PHP-fpm remote code execution vulnerability (CVE-2019-11043).

Familiarize yourself with programming development on Linux platforms, master php, understand languages such as Python, and master data structures and common algorithms.

It is understood that Windows will not completely abandon support for PHP right away and will still develop and build for PHP 7.3 and PHP 7.4. Microsoft also supports appropriate security fixes for PHP 7.2 running on Windows.

Founded in 2006, ThinkPHP is a home-grown open source PHP development framework that draws on the Action objects of the Struts framework, while also using object-oriented development structures and MVC patterns. ThinkPHP runs on operating systems such as Windows and Linux, supports a variety of databases such as MySql, Sqlite, and PostgreSQL, and PDO extensions, and is a cross-platform, cross-version, and easy-to-use PHP framework.

Bitcoin Wallet Electrum now supports Lightning Online Payments According to Coindesk July 11th, Bitcoin Wallet Electrum now supports Lightning Web Payments. It has previously been reported that Bitcoin Wallet Electrum has released a beta version of Electrum 4.0, adding support for the Bitcoin Lightning Network.

Like Bitcoin's core wallet, Electrum Wallet allows users to control their own funds and private keys. Electrum wallets' private keys can also be exported and used on other supported wallets to access funds. Electrum apps are available for Windows, Linux, OSX and Android, but do not support iOS and browser clients.

According to Bleeping Computer, the BTC wallet app Electrom accused a phishing product called Electrum Pro of stealing a user's seed key on May 9 on GitHub and registering a domain name called electrum without Electrum's permission. The Electrum team noted that there was a piece of code indicating that the counterfeit product might have taken the user's seed key and uploaded it to the electrum. Affected users should transfer funds from BTC URLs managed by Eletrum Pro.

As of press time, phishing attacks that forged Electrum upgrade notifications have stolen at least 1,450 BTC (the number stolen is officially counted by a user, anti-malware companies Malwarebytes and Electrum), with a total value of approximately $11.6 million. It is worth mentioning that Electrum versions lower than 3.3.4 are vulnerable to such phishing attacks. Users who use Electrum wallets should update to the latest version Electrum 3.3.8 through the official website (electrum.org). At present, v4.0.0 has not been officially released. Version, please do not use the link in the prompt message to update, so as to avoid loss of assets

Technically, no one has had the money to pay license fees to Sun and Oracle since the dotcom bubble collapsed in 2000. Apache, Linux, mysql, Java and PHP are all in vogue.

Tested the cli mode of php under linux, the apache php_module mode, and the nginx FastCGI mode, with the same results. Under windows you see the diagram from the b1ind master, and the working directory of the destructor is under the apache directory.

People who are engaged in Java, PHP, Linux operations, etc., and want to move into big data hot industries.

Today, while we don't have all the protocols we need to fully realize the full vision of Web 3, for Web 3, it's actually like LAMP (Linux and Apache , MySQL , PHP) or WAMP (Windows and Apache , MySQL , Php), which are passed down from generation to generation, but now we may be approaching the tipping point of market transformation, especially at the ledger/settlement layer.

Electrum posted a message about the incident on Twitter today, claiming that "there are currently phishing attacks against Electrum users" and imploring users to check the validity of their login information.

