Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 12-21-2004, 01:07 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Virus News. Tuesday, December 21, 2004
************************************************** ****************

1. Net-Worm.Perl.Santy.a threatens Internet forums
2. How to subscribe/unsubscribe
3. Security Rules

****

1. Net-Worm.Perl.Santy.a threatens Internet forums

Kaspersky Lab, a leading developer of secure content management systems,
has detected a new worm, Net-Worm.Perl.Santy.a. This worm infects
certain web sites by exploiting a vulnerability in phpBB, a popular
package used to create Internet forums. Santy.a is spreading rapidly,
and has caused an epidemic. However, this does not directly affect end
users - although the worm infects web sites, it does not infect
computers used to view these sites.

Santy.a is something of a novelty - it creates a specially formulated
Google search request, which results in a list of sites running
vulnerable versions of phpBB. It then sends a request containing a
procedure which will trigger the vulnerability to these sites. Once the
attacked server processes the request, the worm will penetrate the site,
gaining control over the resource. It then repeats this routine.

Once the worm has gained control over a site, it will scan all
directories on the infected site. All files with the extensions .htm,
.php, .asp, .shtm, .jsp and phtm will be overwritten with the text 'This
site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm
generation'.

Apart from defacing infected sites with this text, the worm has no
payload. It will not infect machines which are used to view infected
sites. Kaspersky Lab recommends that all users of phpBB should upgrade
to version 2.0.11 to prevent their sites from being defaced.

An urgent update to Kaspersky Anti-Virus databases has already been
issued. Information about Santy.a can be found in the Kaspersky Virus
Encyclopaedia.
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Zotob Suspects Arrested Mobo News & Announcements 0 09-05-2005 10:30 PM
    Mytob Worm LJM Master Security Alerts and vulnerabilities 0 03-31-2005 02:04 PM
    W32/VBSun-A worm pmf45 Security Alerts and vulnerabilities 1 01-17-2005 12:54 PM
    Cellery worm Mobo Security Alerts and vulnerabilities 0 01-13-2005 08:42 AM
    Mass mailing Worm Mobo Security Alerts and vulnerabilities 0 11-19-2004 09:54 AM



    All times are GMT -5. The time now is 10:51 AM.


    Firefox 2