It searches google for victims.
http://news.zdnet.com/2100-1009_22-5499725.html?tag=nl.e589
Net worm using Google to spread
By Robert Lemos CNET News.com December 21, 2004, 11:01 AM PT
A Web worm that identifies potential victims by searching Google is spreading among online bulletin boards using a vulnerable version of the program phpBB, security professionals said on Tuesday.
The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread, according to updated analyses. The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement.
Almost 40,000 sites may have already been infected. Using Microsoft's Search engine to scan for the phrase "NeverEverNoSanity"--part of the defacement text that the Santy worm uses to replace files on infected Web sites--returns nearly 39,000 hits.
"Santy.a is spreading rapidly," antivirus firm Kaspersky stated in a new release published Tuesday. "However, this does not directly affect users. Although the worm infects Web sites, it does not infect computers used to view those sites."
The worm sends Google a specific search request, essentially asking for a list of vulnerable sites. Armed with the list, the worm then attempts to spread to those sites using a PHP request designed to exploit the phpBB bulletin board software.
The worm is the latest twist on using Google as an attack tool, a practice known as Google hacking. It may also be the first time a program used Google to identify victims for an attack.
Around 6 million sites appear to be running the phpBB software, according to a search of Google for the phrase "Powered by phpBB"--an acknowledgment appended to the bottom of any site that uses the software.
"There are tons of these PHP bulletin board installs around," said Johannes Ullrich, chief technology officer of the Internet Storm Center, which tracks online threats. Initial analyses by the ISC had concluded that the flaw exploited by the worm occured in the software that interprets Web pages written scripting language PHP: Hypertext Preprocessor (PHP). That flaw was found last week.
Using Google to determine vulnerable sites is not an academic exercise. The worm does exactly that: Once Santy infects a Web site, it searches Google for other sites running phpBB and then attempts to infect those sites as well.
After it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X," according to Kaspersky. For "X," the worm inserts a number representing how far the current instance of the program is descended from the original worm release. MSN searches have found 24th generations of the worm.
Google did not immediately comment on the worm, but a spokesman did say that the company had seen the information and had started to study the issue.
The response, or lack thereof, frustrated some members of the antivirus community, who believed that the search giant could easily stop the worm by filtering out its search for victims.
"We know exactly which searches to stop," said Mikko Hypponen, research director of antivirus firm F-Secure. "It would be trivial to stop this thing."
Web sites using a vulnerable version of phpBB should upgrade, the phpBB Project site advises.
+ Reply to Thread
Results 1 to 29 of 29
-
-
Damn it, beat me to it
Baldrick is covered, right? -
Is there something wrong with some of the Thread links? I keep getting this...
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1283
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1350
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1350
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1350
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1283
Warning: Empty regular expression in /var/www/html/videohelp/forum/viewtopic.php on line 1350 -
"Each problem that I solved became a rule which served afterwards to solve other problems." - Rene Descartes (1596-1650)
-
edit your last post and it will fix it
"Each problem that I solved became a rule which served afterwards to solve other problems." - Rene Descartes (1596-1650) -
does for me -- just hit edit and and dont even have to change a thing ..
"Each problem that I solved became a rule which served afterwards to solve other problems." - Rene Descartes (1596-1650) -
canadateck: It should be fixed now.
I can't find any php complete 4.3.10 rpm. I have to manually compile the php....million php settings and I don't know if turck mmcache will work. Must this happen right now...I want some holiday...............aASDLASKjdsaldk -
"Each problem that I solved became a rule which served afterwards to solve other problems." - Rene Descartes (1596-1650)
-
Thanks. But I'm thinking of setting up a linux test server first....I have lots of extensions for php and also mmcache that some say wont work with php4.3.10.
I have added some phpbb patches so hopefully wont the site get infected by the santy worm. -
Originally Posted by BaldrickAfter it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X,"
-
I'm still recovering from the last outage.
:P
8)
Nothing can stop me now, 'cause I don't care anymore. -
Baldrick,
Is this on an apache server? Check this out... http://www.phpbb.com/phpBB/viewtopic.php?t=249010 -
Originally Posted by thecoalman
-
Originally Posted by Josef K
-
Originally Posted by Baldrick
-
Don't know if this is some kind of coincidence but one of the google crawlers is constantly loading my phpbb FAQ page. I had an instance where it had loaded it 4 times, just the faq too. Also two spikes in bandwidth because of it, one on Sunday and one yesterday both of which were 4 times my normal bandwidth..... just thought I'd mention it.
-
If it's any consolation, Google appear to be getting their act together on this. From this page:
Once Google started blocking these search queries the rate of infection tailed off sharply.
A message sent to Finnish security firm F-Secure by Google's security team said: "While a seven hour response for something like this is not outrageous, we think we can and should do better."
"We will be reviewing our procedures to improve our response time in the future to similar problems," the Google team said.
The worst of the attack now seems to be over as a search conducted on the morning of the 22 December produced only 1,440 hits for sites showing the text used in the defacement message. -
Originally Posted by Josef K
It's downloaded it enough to come out to around 100MB... WTF
-
Originally Posted by thecoalman
-
Originally Posted by Josef K
-
My server was upgraded to php4.3.10 by my hosting company sometime this afternoon.
-
I could post a topic over at www.linuxquestions.org to find a complete rpm if you still need it.
Similar Threads
-
W2 blaster worm
By jyeh74 in forum Newbie / General discussionsReplies: 30Last Post: 16th Aug 2011, 13:23 -
How to fix a loose s-video plug
By themaster1 in forum RestorationReplies: 17Last Post: 6th Feb 2011, 00:19 -
Does up-converting loose clarity?
By CrackBookPro in forum Video ConversionReplies: 2Last Post: 19th Aug 2010, 16:58 -
BBC reports Storm Worm attack on Blogger
By ahhaa in forum ComputerReplies: 0Last Post: 31st Aug 2007, 09:16 -
Windows Genuine (ahem) Advantage targeted by worm.
By AlecWest in forum ComputerReplies: 0Last Post: 8th May 2007, 19:47