Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 12-21-2004, 12:07 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Virus News. Tuesday, December 21, 2004
************************************************** ****************

1. Net-Worm.Perl.Santy.a threatens Internet forums
2. How to subscribe/unsubscribe
3. Security Rules

****

1. Net-Worm.Perl.Santy.a threatens Internet forums

Kaspersky Lab, a leading developer of secure content management systems,
has detected a new worm, Net-Worm.Perl.Santy.a. This worm infects
certain web sites by exploiting a vulnerability in phpBB, a popular
package used to create Internet forums. Santy.a is spreading rapidly,
and has caused an epidemic. However, this does not directly affect end
users - although the worm infects web sites, it does not infect
computers used to view these sites.

Santy.a is something of a novelty - it creates a specially formulated
Google search request, which results in a list of sites running
vulnerable versions of phpBB. It then sends a request containing a
procedure which will trigger the vulnerability to these sites. Once the
attacked server processes the request, the worm will penetrate the site,
gaining control over the resource. It then repeats this routine.

Once the worm has gained control over a site, it will scan all
directories on the infected site. All files with the extensions .htm,
.php, .asp, .shtm, .jsp and phtm will be overwritten with the text 'This
site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm
generation'.

Apart from defacing infected sites with this text, the worm has no
payload. It will not infect machines which are used to view infected
sites. Kaspersky Lab recommends that all users of phpBB should upgrade
to version 2.0.11 to prevent their sites from being defaced.

An urgent update to Kaspersky Anti-Virus databases has already been
issued. Information about Santy.a can be found in the Kaspersky Virus
Encyclopaedia.
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zotob Suspects Arrested Mobo News & Announcements 0 09-05-2005 09:30 PM
Mytob Worm LJM Master Security Alerts and vulnerabilities 0 03-31-2005 01:04 PM
W32/VBSun-A worm pmf45 Security Alerts and vulnerabilities 1 01-17-2005 11:54 AM
Cellery worm Mobo Security Alerts and vulnerabilities 0 01-13-2005 07:42 AM
Mass mailing Worm Mobo Security Alerts and vulnerabilities 0 11-19-2004 08:54 AM



All times are GMT -5. The time now is 09:46 PM.


Firefox 2