If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
These forums remain online primarily for archival purposes. While posting is still possible, it should not be considered a means for support. Please login to our portal and submit a ticket if you require assistance and we'll be more than happy to assist you.
Regular updates are posted to our blog and we will continue to post important notices to the Script Security forum section here. You can subscribe to that forum to automatically receive notifications.
It looks like this is the latest iteration of a phpBB exploit. Read the following Security bulletin. I am upgrading his phpBB version to 2.0.11 as we speak.
BehaviorNet-WormTechnical DetailsThis worm uses a vulnerability in phpBB, which is used to create forums and web sites, to spread via the Internet. phpBB versions lower than 2.0.11 are vulnerable.
The worm is written in Perl, and is 4966 bytes in size.
Propagation
The worm creates a specially formulated Google search request. This request will give a list of sites running vulnerable versions of phpBB. The worm then sends a request to all sites found, which contains an exploit for the vulnerability. When the server under attack processes the exploit, the worm penetrates the site and gains control. This process is then repeated.
The worm scans all site directories, and overwrites files with the following extensions:
.asp.htm.jsp.php .phtm.shtmwith the following text:
This site is defaced!!!This site is defaced!!!NeverEverNoSanity WebWorm generationUsing MSN to search for sites containing the above strings gives an extensive list of sites; evidence that Santy.a is currently causing an epidemic.
Users should note that this worm is not dangerous; it will not infect computers if users view an infected site.
Net-Worm.Perl.Santy.a
The worm scans all site directories, and overwrites files with the following extensions:
.asp.htm.jsp.php .phtm.shtmwith the following text:
This site is defaced!!!This site is defaced!!!NeverEverNoSanity WebWorm generationUsing MSN to search for sites containing the above strings gives an extensive list of sites; evidence that Santy.a is currently causing an epidemic.
Users should note that this worm is not dangerous; it will not infect computers if users view an infected site.
Why not use .htaccess to force PHP to phrase, say, .file or some
off the wall extention? Maybe the initials of the site?
Though for something like forums, it'd not be worth it
"How can someone be so distracted yet so focused?"
- C
One of my sites got hit ... but the rest appear to be OK. Dathorn has upgraded Cpanel08 to the most recent PHP version that is supposed to protect us, so we'll see.
I hope it only affected the index.php files ... if it did them all, we'll have to restore them all! That would be a pain.
Comment