Real-world SSC attacks
Most of the SSC discussion to this point has been conceptual. The next section will highlight some examples of attacks on the SSC to illustrate how they can happen and the damage they can cause.
PHP: No harm, but foul
Based on a multi-year tracking survey by W3Techs, the PHP programming language was the backend language for over 80% of websites from 2014 to 2018, a figure that was still above 75%, as of February 2024.6
As mentioned in Chapter 1, Git is a protocol and system for source code management and version control. GitHub neither invented it nor owns it, but they are the most prominent commercial host of it for developers around the world.
PHP is an open source project hosted on its own Git server. In 2021, the server was breached and two backdoors were not only inserted in the source code for the programming language, but they were committed under the...