hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : new phpBB worm effects ALL versions
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

new phpBB worm effects ALL versions

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 12-25-2004, 03:19 PM
eth00 eth00 is offline
Web Hosting Master
 
Join Date: Apr 2003
Location: NC
Posts: 2,911

new phpBB worm effects ALL versions


http://www.securityfocus.com/archive...2/2004-12-28/0

Apparently the new version will work with any version of phpBB even 2.0.11. It also includes irc code to connect to a server, probably for a botnet.

They are still using the code for highlighting to get in.

__________________
John W
www.eth0.us

Reply With Quote


Sponsored Links
  #2  
Old 12-25-2004, 03:23 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,591
Heh if this is real im going to laugh at all the people that patched patched patched instead of securing their server Told you patching was bad. However i have my doubts of it working...I'll check it shortly.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #3  
Old 12-25-2004, 03:49 PM
flamesburn flamesburn is offline
Junior Guru
 
Join Date: Jul 2002
Posts: 206
phpbb is starting to be a pain to deal with all the holes.

__________________
Cooper.
FlamesBurn.com

Reply With Quote
Sponsored Links
  #4  
Old 12-25-2004, 04:01 PM
PhilG PhilG is offline
Web Hosting Evangelist
 
Join Date: Feb 2003
Posts: 543
this is amazing!

__________________
Off Topic Web Forum - A forum for talking about anything!!
N.Z. Webmaster Community - Are you from New Zealand? Well signup to our forum!!!!

Reply With Quote
  #5  
Old 12-25-2004, 04:19 PM
andreyka andreyka is offline
Linux Guru
 
Join Date: Mar 2004
Location: Odessa, Ukraine
Posts: 604
LOL, old hole!
Just disable system() fuction in php.ini and frogot about this "worm"

__________________
My CVV Page

Reply With Quote
  #6  
Old 12-25-2004, 04:20 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,591
Quote:
Originally posted by andreyka
LOL, old hole!
Just disable system() fuction in php.ini and frogot about this "worm"
Hah your funny... Passthru, exec, shell_exec, open can all be used in the exploit. Also disabling the functions is not feasable on some servers.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #7  
Old 12-25-2004, 04:26 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,591
http://www.k-otik.com/exploits/20041225.SantyC.php

Quote:
This script uses Google to find vulnerable *.php pages to a file inclusion flaw (See - PHP Secure Prog.)
So any vulnerable php that had a file include exploit is vulnerable.... example phpnuke

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #8  
Old 12-25-2004, 04:34 PM
andreyka andreyka is offline
Linux Guru
 
Join Date: Mar 2004
Location: Odessa, Ukraine
Posts: 604
Quote:
Originally posted by thelinuxguy
Hah your funny... Passthru, exec, shell_exec, open can all be used in the exploit. Also disabling the functions is not feasable on some servers.
Well, for shared hostings disablie this functions as well, from some servers... mod_security can help

__________________
My CVV Page

Reply With Quote
  #9  
Old 12-25-2004, 04:35 PM
tpetersen tpetersen is offline
Web Hosting Guru
 
Join Date: May 2003
Location: Virginia
Posts: 299
Quote:
Originally posted by flamesburn
phpbb is starting to be a pain to deal with all the holes.
Starting to be a pain? 

Reply With Quote
  #10  
Old 12-25-2004, 04:37 PM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,591
Quote:
Originally posted by andreyka
Well, for shared hostings disablie this functions as well, from some servers... mod_security can help
There is other things you can do with out disabling those functions.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #11  
Old 12-25-2004, 06:42 PM
jessfx jessfx is offline
Junior Guru Wannabe
 
Join Date: Jan 2004
Posts: 40
I got attacked by Shellbot before Sanity ... Sanity hit me, but i had disabled sites with phpbb already.

Still not quite sure how shellbot is infecting my box, unless it uses HTTP-POST instead of GET. I can not find it in the logs.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
McAfee Predicts Evolution of Security Threats in 2013 Report Web Hosting News 2012-12-27 15:19:04
Softaculous Releases Auto Installer Version 4.1.7 Web Hosting News 2012-12-19 16:45:21
Security Provider Websense Discovers Fake Symantec Emails Distributing Malware Web Hosting News 2012-08-29 14:44:19
Microsoft Updates Licensing, Offers Four Versions of Windows Server 2012 Web Hosting News 2012-07-06 10:31:48
Hosting Software Firm Softaculous Releases Version 4.0 Web Hosting News 2012-01-23 13:54:44


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?