Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
3 registered (Mike L, Ruben, SteveS), 50 Guests and 12 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 05/22/12
Posts: 2
Top Posters (30 Days)
Ruben 49
Gizmo 24
DennyP 23
Dunny 19
SteveS 14
AllenAyres 12
dbremer 10
SD 9
drkknght00 9
Pilgrim 7
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Topic Options
#113880 - 12/21/04 06:15 PM [NOTABUG] Net.Worm.Perl.Santy-A
Hertz Offline
stranger
Registered: 09/14/04
Posts: 1
We've had 6.7.2 breached by this worm:

http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1036174,00.html

The only crucial file it got was ultimatebb.php, but that's enough to bring down most the board....

Any suggestions?
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#113881 - 12/21/04 06:27 PM Re: [NOTABUG] Net.Worm.Perl.Santy-A
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
UBB.classic is not a vector for this worm - it only infects phpBB boards.

The worm, once attached to the board, proceeds to scour the server for writable files with certain extensions, which then proceed to get overwritten with the worm's message.

Your server has a phpBB running on it somewhere that was infected, and proceeded to jump boundaries into your account (and surely everyone else's on that server) and do its work.

Again, there is no way for UBB.classic (or UBB.threads) to be a vector for this worm.
_________________________
This thread for sale. Click here!
Top
#113882 - 12/26/04 08:00 PM Re: [NOTABUG] Net.Worm.Perl.Santy-A
Unnet Board Guy Offline
newbie
Registered: 08/19/04
Posts: 28
Hi Charles and brushiefish,

I had two ubb.classic forums that are no longer up because of something ? I'm not certain if it's this worm or not, but I've taken them both down and had to have the server re-built. I wasn't using a php database or anything else that I think could have been compromised. Just html and the ubb classic forum. I'm not an expert by any means but .... there it is.
Top
#113883 - 12/27/04 01:20 PM Re: [NOTABUG] Net.Worm.Perl.Santy-A
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
It is unlikely that the worm was the cause unless the file destruction matches that which is described in the article posted above.
_________________________
This thread for sale. Click here!
Top
#113884 - 12/28/04 10:25 AM Re: [NOTABUG] Net.Worm.Perl.Santy-A
Unnet Board Guy Offline
newbie
Registered: 08/19/04
Posts: 28
Hi Charles,

Thank you for your reply. You may want to read this article:

http://www.computerworld.com/securitytopics/security/holes/story/0,10801,98553,00.html?from=homeheads

Sincerely
Top
#113885 - 12/28/04 10:26 AM Re: [NOTABUG] Net.Worm.Perl.Santy-A
Unnet Board Guy Offline
newbie
Registered: 08/19/04
Posts: 28
::
Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software (see story). However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warned.
Top
#113886 - 12/28/04 02:32 PM Re: [NOTABUG] Net.Worm.Perl.Santy-A
David Dreezer Offline

Pooh-Bah
Registered: 07/21/06
Posts: 2199
No Infopop products are vulnerable to any existing version of the Santy worm.
_________________________
This thread for sale. Click here!
Top



Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Island Permissions
by ThreadsUser
03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Custom forum permissions
by ntdoc
05/18/12 02:07 PM
Running ads
by Jeffdag
05/17/12 01:47 PM
Forum Stats
10481 Members
36 Forums
33832 Topics
181676 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image