|
|
Joined: Sep 2004
Posts: 1
stranger
|
stranger
Joined: Sep 2004
Posts: 1 |
We've had 6.7.2 breached by this worm: http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1036174,00.html The only crucial file it got was ultimatebb.php, but that's enough to bring down most the board.... Any suggestions?
|
|
|
|
Joined: Jul 2006
Posts: 2,143
Pooh-Bah
|
Pooh-Bah
Joined: Jul 2006
Posts: 2,143 |
UBB.classic is not a vector for this worm - it only infects phpBB boards.
The worm, once attached to the board, proceeds to scour the server for writable files with certain extensions, which then proceed to get overwritten with the worm's message.
Your server has a phpBB running on it somewhere that was infected, and proceeded to jump boundaries into your account (and surely everyone else's on that server) and do its work.
Again, there is no way for UBB.classic (or UBB.threads) to be a vector for this worm.
|
|
|
|
Joined: Aug 2004
Posts: 28
newbie
|
newbie
Joined: Aug 2004
Posts: 28 |
Hi Charles and brushiefish,
I had two ubb.classic forums that are no longer up because of something ? I'm not certain if it's this worm or not, but I've taken them both down and had to have the server re-built. I wasn't using a php database or anything else that I think could have been compromised. Just html and the ubb classic forum. I'm not an expert by any means but .... there it is.
|
|
|
|
Joined: Jul 2006
Posts: 2,143
Pooh-Bah
|
Pooh-Bah
Joined: Jul 2006
Posts: 2,143 |
It is unlikely that the worm was the cause unless the file destruction matches that which is described in the article posted above.
|
|
|
|
Joined: Aug 2004
Posts: 28
newbie
|
newbie
Joined: Aug 2004
Posts: 28 |
:: Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software (see story). However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warned.
|
|
|
|
Joined: Jul 2006
Posts: 2,143
Pooh-Bah
|
Pooh-Bah
Joined: Jul 2006
Posts: 2,143 |
No Infopop products are vulnerable to any existing version of the Santy worm.
|
|
|
2 members (Ruben, Gizmo),
1,116
guests, and
116
robots. |
Key:
Admin,
Global Mod,
Mod
|
|
|
|
|