Welcome our webmaster and SEO forum
Please enjoy the forum, contribute what you can, and wind up the Moderators!
Results 1 to 3 of 3

Thread: phpbb vulnerability

  1. #1
    ovi Guest

    Default phpbb vulnerability

    A worm using Google to identify websites that use a vulnerable type of bulletin board software has spread quickly, infecting up to 40,000 sites.
    The worm, dubbed Santy, exploits a vulnerability in third-party web servers that use phpBB bulletin board software, a popular package used to create web forums, and has been propagating at a rapid pace, infecting some 38,000 sites in a matter of hours.
    This latest worm is quite unique, according to Kaspersky Lab. Santy creates a Google search request, which provides it with a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure which will trigger the vulnerability to these sites. Once the attacked server processes the request, Santy wriggles into the site and gains control.
    Infected bulletin boards will feature a text message saying "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation". Security experts have said that the worm will not attack home users but they may see its affects if they access the contaminated bulletin boards.
    Google has proven to be a good hunting ground for worm authors who have used it to harvest e-mail addresses. Earlier in 2004 the MyDoom virus used Google in this way, pumping so many search queries into Google that the search engine was disabled for large periods of time.
    Google has responded to pressure from antivirus firms to stop the spread of the worm. The search giant has told Kapersky Lab that it has begun to filter requests made by Santy in a bid to halt the worm's spread.
    Kaspersky Lab has advised that all users of phpBB to upgrade to version 2.0.11 in order to prevent their sites from being defaced by the Santy worm.

    Full story can be read here: newsmakers.co.uk

  2. #2
    Darksat Guest

    Default

    The most effective way of stopping worms like that is to remove the version number of your PHPBB forum from the footer.
    that way you avoid people/worms who are looking for version speific targets

  3. #3
    Paul_KY is offline Senior Member
    Join Date
    Aug 2004
    Posts
    1,285

    Default

    Speaking of, "Removing Worms"...

    This POS needs to be REMOVED. Either that, or BAN me.

    He'll be in JAIL soon, anyway...
    "There's no such thing as impossible. It's a myth. Don't believe it."

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 1
    Last Post: 10-08-2007, 01:39 PM
  2. phpbb to vbulletin
    By gkd_uk in forum General Webmaster Talk
    Replies: 2
    Last Post: 06-26-2007, 09:03 AM
  3. New Vulnerability
    By ovi in forum In The News
    Replies: 0
    Last Post: 01-14-2005, 02:40 PM
  4. Vulnerability in Google Groups
    By Darksat in forum General Search Engine Discussions
    Replies: 0
    Last Post: 12-19-2004, 11:16 AM
  5. Welcome to phpBB 2
    By imported_misi in forum New Members Introduction
    Replies: 0
    Last Post: 10-21-2000, 12:01 AM

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124