Net worm using Google to spread

Posted on Wednesday, December 22, 2004 @ 06:48:10 CST in Security
by Raven

manunkind writes:  
A Web worm that identifies potential victims by searching Google is spreading among online bulletin boards using a vulnerable version of the program phpBB, security professionals said on Tuesday. The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread, according to updated analyses. The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement. Almost 40,000 sites may have already been infected. Using Microsoft's Search engine to scan for the phrase "NeverEverNoSanity"--part of the defacement text that the Santy worm uses to replace files on infected Web sites--returns nearly 39,000 hits. "Santy.a is spreading rapidly," antivirus firm Kaspersky stated in a new release published Tuesday. "However, this does not directly affect users. Although the worm infects Web sites, it does not infect computers used to view those sites."
 
 
click Related        click Share
 
 

Re: Net worm using Google to spread (Score: 1)
by chiumanfu on Wednesday, December 22, 2004 @ 10:53:48 CST
  
(User Info | Send a Message)

Is this related to the urldecode hole. Is my phpbb immune if I made that fix?

 
 

Re: Net worm using Google to spread (Score: 1)
by cprompt on Wednesday, December 22, 2004 @ 11:10:29 CST

(User Info | Send a Message)

This is legit: Patch your site IMMEDIATELY!

Fix:
http://www.phpbb.com/phpBB/viewtopic.php?t=240513

More Info:
http://www.f-secure.com/v-descs/santy_a.shtml

 
 

Re: Net worm using Google to spread (Score: 1)
by molten2 on Wednesday, December 22, 2004 @ 14:20:07 CST

(User Info | Send a Message) http://www.adamantio.net

This worm only affect versions before 2.0.11:
Worm.Perl.Santy.a can infect certain phpBB forums?

Upgrade your version of phpbb-nuke from Nuke Resources:
BBtoNuke 2.0.11 [www.nukeresources.com]

 
News ©

Site Info

Last SeenLast Seen
  • moekin
  • kguske
Server TrafficServer Traffic
  • Total: 506,362,066
  • Today: 136,039
Server InfoServer Info
  • Mar 20, 2025
  • 06:56 pm CDT