Hunting for PHPUnit Installed via Composer, (Tue, Nov 30th)

One rather persistent pattern in our honeypot logs is attacks against older PHPUnit flaws. These attacks appear to exploit %%cve:2017-9841%%, a simple remote code execution vulnerability [1]. Back in 2019, Imperva called it “one of the most exploitable CVEs of 2019”, and even now, attacks keep coming in [2]. After tuning one of our honeypots to be more sensitive to these attacks, we saw one to two thousand attacks against the honeypot a day (the honeypot covers multiple IP addresses).

Article Link: InfoSec Handlers Diary Blog