forum virus

Discussion in 'Operativni sistemi, aplikacije i programiranje' started by iskusni, Dec 22, 2004.

  1. iskusni

    iskusni Komšija

    Posted by Hilbert Hagedoorn

    Kaspersky Lab is reporting that they have detected a new worm, Net-Worm.Perl.Santy.a. This worm infects certain web sites by exploiting a vulnerability in phpBB, a popular package used to create Internet forums. We run other software and seem to be safe. Santy.a is spreading rapidly, and has caused an epidemic. However, this does not directly affect end users - although the worm infects web sites, it does not infect computers used to view these sites.

    Santy.a is something of a novelty - it creates a specially formulated Google search request, which results in a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure which will trigger the vulnerability to these sites. Once the attacked server processes the request, the worm will penetrate the site, gaining control over the resource. It then repeats this routine.

    Once the worm has gained control over a site, it will scan all directories on the infected site. All files with the extensions .htm, .php, .asp, .shtm, .jsp and phtm will be overwritten with the text 'This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation'.

    Apart from defacing infected sites with this text, the worm has no payload. It will not infect machines which are used to view infected sites. Kaspersky Lab recommends that all users of phpBB should upgrade to version 2.0.11 to prevent their sites from being defaced.

    Source: kaspersky.com
     
  2. syss

    syss Veteran foruma

    napao je links.hr taj virus, pa je bilo problema skoro 2 dana.

    kolko sam čuo nova verzija phpbb foruma (2.0.11) ispravlja tu rupu.
     
  3. Esh

    Esh HWB

    done:)
     
  4. syss

    syss Veteran foruma

    primjetio sam... probao sam se ulogirat malo prije, pa ništa.

    bitno je da mi surađujemo :wink:
     
  5. Shenron

    Shenron Komšija

    Jesi probao onu.. 2.2 verziju? Ima stvarno pun qrac opcija...jest da sam se malo namucio sa instalacijom...pa sam nakon 2h supanja po forumu sve ponovo sjebao :mrgreen:
     
  6. Esh

    Esh HWB

    samo stabilne verzije preferiram 8)