Jump to content

  • Log in with Facebook Log in with Twitter Log In with Google      Sign In   
  • Create Account

Subscribe to HRA Now!

 



Are you a Google Analytics enthusiast?

Share and download Custom Google Analytics Reports, dashboards and advanced segments--for FREE! 

 



 

 www.CustomReportSharing.com 

From the folks who brought you High Rankings!


Sponsored Content

 

 
 

Photo
- - - - -

Worm Using Google To Attack Phpbb


  • Please log in to reply
3 replies to this topic

#1 DaveBeck

DaveBeck

    HR 3

  • Active Members
  • PipPipPip
  • 102 posts
  • Location:Australia

Posted 23 December 2004 - 04:27 AM

Apparently the "Santy" worm is exploiting a vulnerability in phpBB by searching Google for the term "Powered by phpBB".

If it finds a vulnerable installation of the worm will remove any HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X.

Worm uses Google to spread

I guess anybody using this form software needs to head straight over to the phpBB Web site and make sure that they have the latest version wink.gif

dave

#2 Randy

Randy

    Convert Me!

  • Moderator
  • 17,540 posts

Posted 23 December 2004 - 08:36 AM

I didn't read all of it for the details, but it sounds like it may be related to a recently documented security flaw in PHP itself, not something specifically in PHPbb.

If your site is on an affected server, please contact your hosting company to make sure they apply the appropriate patch for PHP. Gonna start a thread on that in just a sec since I'm not 100% sure this is related, and the overall PHP vulnerability will affect far more.

#3 Tom Philo

Tom Philo

    Photographer

  • Active Members
  • PipPipPipPipPip
  • 507 posts
  • Location:Beaverton, Oregon

Posted 23 December 2004 - 11:40 AM

Google yesterday (or maybe Tuesday) wrote high level code to block the worm from searching Google in order for it to find sites running the PHPBB script which had not been infected yet.

The term "Powered by phpBB" was required to be on the home page thus it did a unique search in Google to find those sites running it then replicate itself to the first site it found in the list (or maybe a number of sites, I did not read the details of how it completely works and replicates).

In Google this AM I see 295 references to the full defacement text but likely 1/2 of those are news articles about it.

#4 OldWelshGuy

OldWelshGuy

    Work is Fun

  • Moderator
  • 4,713 posts
  • Location:Neath, South Wales, UK

Posted 23 December 2004 - 12:37 PM

It took Google 7 hours to identify the threat, and code a solution to it.

So, all you Google bashers out there, you gptta love that. I mean how cool is that?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users