ZAM
Inventar
New worm Santy has started spreading. This one is infected only web servers, not end user computers. In fact, it infects sites running the popular phpBB discussion forum software.
Many sites are already affected...the end result typically looks like this:
http://www.f-secure.com/weblog/archives/santy.jpg
Apparently version 2.0.11 of phpBB is not vulnerable to the Santy worm. That's according to the description of the apparent vulnerability ("viewtopic.php highlight") posted to Securiteam's site.
This worm is written in Perl. It's searching vulnerable forum sites via Google. When a suitable site is found, the worm uses a remote exploit to gain access to it, defaces it and restarts random scanning for new hosts.
There has been several serious holes in the phpBB software over the years. One was discussed in Netcraft just days ago.
We don't know how many phpBB sites there are in the world, but Google search for inurl:phpbb inurl:viewtopic gives over a million hits...
The first defacement we heard about happened today at around 15:00 GMT.
Official home page of phpBB does not mention this incident yet.
Quelle: http://www.f-secure.com

