Go Back   Webmaster Forums UK SEO SEM Webmaster Community Forum - UKWW > Business Discussions > Business Forum > In The News
Register FAQ Members List Downloads Calendar Today's Posts Webmaster Resources Webmaster Blogs
 
 

In The News Webmastering, information technology and related information currently in the new.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-22-2004, 07:24 PM
ovi
Guest
 
Posts: n/a
Default phpbb vulnerability

A worm using Google to identify websites that use a vulnerable type of bulletin board software has spread quickly, infecting up to 40,000 sites.
The worm, dubbed Santy, exploits a vulnerability in third-party web servers that use phpBB bulletin board software, a popular package used to create web forums, and has been propagating at a rapid pace, infecting some 38,000 sites in a matter of hours.
This latest worm is quite unique, according to Kaspersky Lab. Santy creates a Google search request, which provides it with a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure which will trigger the vulnerability to these sites. Once the attacked server processes the request, Santy wriggles into the site and gains control.
Infected bulletin boards will feature a text message saying "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation". Security experts have said that the worm will not attack home users but they may see its affects if they access the contaminated bulletin boards.
Google has proven to be a good hunting ground for worm authors who have used it to harvest e-mail addresses. Earlier in 2004 the MyDoom virus used Google in this way, pumping so many search queries into Google that the search engine was disabled for large periods of time.
Google has responded to pressure from antivirus firms to stop the spread of the worm. The search giant has told Kapersky Lab that it has begun to filter requests made by Santy in a bid to halt the worm's spread.
Kaspersky Lab has advised that all users of phpBB to upgrade to version 2.0.11 in order to prevent their sites from being defaced by the Santy worm.

Full story can be read here: newsmakers.co.uk
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 12-22-2004, 11:55 PM
Darksat
Guest
 
Posts: n/a
Default

The most effective way of stopping worms like that is to remove the version number of your PHPBB forum from the footer.
that way you avoid people/worms who are looking for version speific targets
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 12-23-2004, 02:27 AM
Senior Member
2 posts this year. needs some grease!
New user, who has not interacted much yet.
 
Join Date: Aug 2004
Posts: 1,451
Thanks: 0
Thanked 0 Times in 0 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Send a message via Yahoo to Paul_KY
Default

Speaking of, "Removing Worms"...

This POS needs to be REMOVED. Either that, or BAN me.

He'll be in JAIL soon, anyway...
__________________
"There's no such thing as impossible. It's a myth. Don't believe it."
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Webmaster Resources
UK WW SEO Tools
Find UK Hosts
 
The Forum Rules
Forum Rules - MUST READ
 
Site Of the Month
BizzFace
Nominate site of the month
 
Tag Cloud
43. wholesale adsense ready apple iphone 16gb apple iphone 16gb 3g articles article writer australia web hosting beauty cash casino cheap clothes communications content custard media database dgital camerals domain name english teacher fantasy football fantasy football league fittness football league free handbags home income instant jewelry links link sale medical health money money making online music natural health news nokia n96 16gb one way links online online shop poker professor quality links replica sam allcock seo social networking sony vaio laptop sunglasses technology the medical plus themes tutor verbalized wallet wallets wanted web hosting widget ready wordpress xmas offer

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gmail cookie vulnerability exposes user's privacy temi Google 1 10-08-2007 01:39 PM
phpbb to vbulletin gkd_uk General Webmaster Talk 2 06-26-2007 09:03 AM
New Vulnerability ovi In The News 0 01-14-2005 03:40 PM
Vulnerability in Google Groups Darksat General Search Engine Discussions 0 12-19-2004 12:16 PM
Welcome to phpBB 2 imported_misi New Members Introduction 0 10-21-2000 12:01 AM


All times are GMT. The time now is 07:57 AM.

UK Webmaster World Forums - Internet marketing, web development, domain names, SEO contest and discussuons.
Subscribe to our feeds   Subscribe to our feeds

Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0