LowRider
22-12-2004, 11:20 PM
By John Leyden
Published Tuesday 21st December 2004 23:38 GMT
A worm which attacks web servers running the popular phpBB discussion forum software to deface vulnerable systems spread widely across the net today.
The Santy worm searches for vulnerable forum sites using Google. When a suitable target is found, Santy uses a remote exploit to gain access and deface it before resuming its scanning activity. Content on defaced sites is replaced by the following text string.
"This site is defaced!!!" NeverEverNoSanity
Apart from defacing infected sites with this text, the worm has no payload. It will not infect PC used to view infected sites. F-Secure, the Finnish anti-virus firmm estimates there more than one million sites use the vulnerable phpBB software, of which tens of thousands have already been defaced. Users of phpBB are advised to update to version 2.0.11. ®
I have talked to our hosts and they said there is nothing to worry about, the board has sufficinet anti virus software installed to protect against this. Just incase i wil back all the information onto my computer so its stored.
LowRider
Published Tuesday 21st December 2004 23:38 GMT
A worm which attacks web servers running the popular phpBB discussion forum software to deface vulnerable systems spread widely across the net today.
The Santy worm searches for vulnerable forum sites using Google. When a suitable target is found, Santy uses a remote exploit to gain access and deface it before resuming its scanning activity. Content on defaced sites is replaced by the following text string.
"This site is defaced!!!" NeverEverNoSanity
Apart from defacing infected sites with this text, the worm has no payload. It will not infect PC used to view infected sites. F-Secure, the Finnish anti-virus firmm estimates there more than one million sites use the vulnerable phpBB software, of which tens of thousands have already been defaced. Users of phpBB are advised to update to version 2.0.11. ®
I have talked to our hosts and they said there is nothing to worry about, the board has sufficinet anti virus software installed to protect against this. Just incase i wil back all the information onto my computer so its stored.
LowRider