Previous Thread
Next Thread
Print Thread
Hop To
[NOTABUG] Net.Worm.Perl.Santy-A #113880 12/21/2004 6:15 PM
Joined: Sep 2004
Posts: 1
Hertz Offline OP
stranger
OP Offline
stranger
Joined: Sep 2004
Posts: 1
We've had 6.7.2 breached by this worm:

http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1036174,00.html

The only crucial file it got was ultimatebb.php, but that's enough to bring down most the board....

Any suggestions?

Re: [NOTABUG] Net.Worm.Perl.Santy-A #113881 12/21/2004 6:27 PM
Joined: Jul 2006
Posts: 2,143
David Dreezer Offline
Pooh-Bah
Offline
Pooh-Bah
Joined: Jul 2006
Posts: 2,143
UBB.classic is not a vector for this worm - it only infects phpBB boards.

The worm, once attached to the board, proceeds to scour the server for writable files with certain extensions, which then proceed to get overwritten with the worm's message.

Your server has a phpBB running on it somewhere that was infected, and proceeded to jump boundaries into your account (and surely everyone else's on that server) and do its work.

Again, there is no way for UBB.classic (or UBB.threads) to be a vector for this worm.


This thread for sale. Click here! [Linked Image from navaho.infopop.cc]
Re: [NOTABUG] Net.Worm.Perl.Santy-A #113882 12/26/2004 8:00 PM
Joined: Aug 2004
Posts: 28
Unnet Board Guy Offline
newbie
Offline
newbie
Joined: Aug 2004
Posts: 28
Hi Charles and brushiefish,

I had two ubb.classic forums that are no longer up because of something ? I'm not certain if it's this worm or not, but I've taken them both down and had to have the server re-built. I wasn't using a php database or anything else that I think could have been compromised. Just html and the ubb classic forum. I'm not an expert by any means but .... there it is.

Re: [NOTABUG] Net.Worm.Perl.Santy-A #113883 12/27/2004 1:20 PM
Joined: Jul 2006
Posts: 2,143
David Dreezer Offline
Pooh-Bah
Offline
Pooh-Bah
Joined: Jul 2006
Posts: 2,143
It is unlikely that the worm was the cause unless the file destruction matches that which is described in the article posted above.


This thread for sale. Click here! [Linked Image from navaho.infopop.cc]
Re: [NOTABUG] Net.Worm.Perl.Santy-A #113884 12/28/2004 10:25 AM
Joined: Aug 2004
Posts: 28
Unnet Board Guy Offline
newbie
Offline
newbie
Joined: Aug 2004
Posts: 28
Hi Charles,

Thank you for your reply. You may want to read this article:

http://www.computerworld.com/securitytopics/security/holes/story/0,10801,98553,00.html?from=homeheads

Sincerely

Re: [NOTABUG] Net.Worm.Perl.Santy-A #113885 12/28/2004 10:26 AM
Joined: Aug 2004
Posts: 28
Unnet Board Guy Offline
newbie
Offline
newbie
Joined: Aug 2004
Posts: 28
::
Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software (see story). However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warned.

Re: [NOTABUG] Net.Worm.Perl.Santy-A #113886 12/28/2004 2:32 PM
Joined: Jul 2006
Posts: 2,143
David Dreezer Offline
Pooh-Bah
Offline
Pooh-Bah
Joined: Jul 2006
Posts: 2,143
No Infopop products are vulnerable to any existing version of the Santy worm.


This thread for sale. Click here! [Linked Image from navaho.infopop.cc]

Forum Search
ShoutChat Box
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Mobile app?
by Baldeagle - 12/06/2019 9:32 PM
How do you change Text Line spacing?
by jorb - 11/23/2019 12:14 AM
What happened to FAQ or Forum Help
by Ruben - 11/20/2019 11:58 AM
Search feature encountering an Error message
by jorb - 11/20/2019 12:06 AM
Followed List v7.7.2 Question
by Ruben - 11/12/2019 12:22 PM
Who's Online Now
2 registered members (Gizmo, Baldeagle), 75 guests, and 375 spiders.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Amusing Terain Scenics
Amusing Terain Scenics
by isaac, August 19
Sky places
Sky places
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Snapshot build 20191023)