stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Santy Worm Defaces Web Forums







Santy Worm Defaces Web Forums

Santy Worm Defaces Web Forums 12/22/2004 01:35 AM

The Internet worm is squirming through Web servers that are running unpatched versions of the popular phpBB Web forum software. Santy uses Google search to randomly find sites running phpBB and then overwrites files.




This is a GrokNews Entry: (what is grok?)





Similar Items

Santy Worm Defaces Web Forums

Grok Headline matches for Santy Worm Defaces Web Forums

Santy worm defaces thousands of sites


Santy worm defaces thousands of sites 12/22/2004 01:07 AM

Net-Worm.Perl.Santy.a threatens Internet
forums


Net-Worm.Perl.Santy.a threatens Internet
forums
12/22/2004 01:17 AM

Re: New Santy-Worm attacks *all*
PHP-skripts ( Santy.c ? )


Re: New Santy-Worm attacks *all*
PHP-skripts ( Santy.c ? )
12/25/2004 05:08 PM
K-OTiK Security (Dec 25 2004)

The Santy worm mutates


The Santy worm mutates 12/28/2004 05:37 PM
TechSpot Dec 28 2004 9:42PM GMT

New Santy Worm Threatens More Sites


New Santy Worm Threatens More Sites 12/27/2004 03:53 PM
Techzonez Dec 27 2004 7:52PM GMT

Santy Worm Hits AOL, Yahoo


Santy Worm Hits AOL, Yahoo 12/28/2004 12:49 PM
Enterprise Security Today Dec 28 2004 4:49PM GMT

Google smacks down Santy worm


Google smacks down Santy worm 12/24/2004 12:27 PM
Google said it was blocking searches generated by a new worm, Santy.A, which were being used to find and infect vulnerable computers on the Internet.

New worm, Santy.A, using Google to
spread


New worm, Santy.A, using Google to
spread
12/22/2004 12:58 AM
Antivirus companies are warning Internet users of a new, fast-spreading worm that uses the Google search engine to infect Web servers running a popular package of online bulletin board software.

New worm, Santy, using Google to spread


New worm, Santy, using Google to spread 12/22/2004 01:52 AM
Antivirus companies are warning Internet users about a fast-spreading new worm that infects Web servers running a popular package of online bulletin board software, and uses the Google search engine to find vulnerable servers to infect.

Anti-Santy worm on the prowl


Anti-Santy worm on the prowl 12/31/2004 12:32 PM
ZDNet Dec 31 2004 5:10PM GMT

Anti-Santy worm spreads


Anti-Santy worm spreads 12/31/2004 09:02 AM
ZDNet UK Dec 31 2004 1:20PM GMT

New Santy-Worm attacks *all* PHP-skripts


New Santy-Worm attacks *all* PHP-skripts 12/25/2004 05:09 PM
Juergen Schmidt (Dec 25 2004)

Santy Worm Varients Spreading


Santy Worm Varients Spreading 12/28/2004 07:14 PM
As we reported last week, Google had been used by the "Santy.A" worm to infect websites using vulnerable versions of phpBB. Google has since disallowed such search attempts by the worm, by simply not listing vulnerable sites in their search results.

Variants are now attempting to exploit search engines offered by Yahoo and AOL, targeting sites running versions of phpBB prior to version 2.0.11. Some variants of the worm damage sites using poorly coded php instances of include() and require(). AOL claims that they are now unaffected, but Yahoo has yet to comment on their security status.

Santy deletes content from effected php-based sites, and replaces it with information found within the worm itself. Luckily this worm is not communicable to computers who visit effected sites. Sites using older versions of phpBB should update immediately, and some sites utilizing php may have to be rewritten all together.

View: Google's Response @ F-Secure Virus Lab Blog

Read full story...

Google squashes Santy worm


Google squashes Santy worm 12/22/2004 01:41 AM
Search firm shuts off ability of worm--which searched for victims via Google--to replicate.

Google blocks Web worm Santy.A


Google blocks Web worm Santy.A 12/29/2004 08:44 PM
The Hindu Business Line Dec 30 2004 12:40AM GMT

Santy worm now targets Yahoo and AOL


Santy worm now targets Yahoo and AOL 12/28/2004 09:28 PM
Pravda Dec 29 2004 1:50AM GMT

Santy worm Targets AOL Yahoo


Santy worm Targets AOL Yahoo 12/28/2004 11:11 PM
WebProNews Dec 29 2004 3:43AM GMT

Google stops spread of Santy worm


Google stops spread of Santy worm 12/24/2004 12:36 PM

Google Becomes Unwitting Abettor for
Santy Worm


Google Becomes Unwitting Abettor for
Santy Worm
12/22/2004 01:44 AM

The new Santy worm uses the Google search engine to find vulnerable websites and then defaces the sites' bulletin boards. The worm, formally named Net-Worm.Perl.Santy, attacks website bulletin boards (Internet forums or message centers) running versions of the popular phpBB bulletin board application. The worm exploits a known security vulnerability in early releases of the phpBB application, defacing the contents of the bulletin board.


BBC: Santy Worm Makes Unwelcome Visit


BBC: Santy Worm Makes Unwelcome Visit 12/24/2004 01:04 PM
"Thousands of website bulletin boards have been defaced by a virus that used Google to spread across the net..."

Other News: Santy worm takes new tack


Other News: Santy worm takes new tack 12/28/2004 03:33 AM
The Santy worm, which originally used Google searches to locate vulnerable phpBB installations, has now mutated to use AOL and Yahoo instead.

Santy PHP Worm Variant With 50 Exploits
Discovered


Santy PHP Worm Variant With 50 Exploits
Discovered
01/02/2005 02:05 PM

Google Nukes Santy Worm, But Threat
Remains


Google Nukes Santy Worm, But Threat
Remains
12/24/2004 12:17 PM
Extreme Tech Dec 24 2004 3:33PM GMT

Anti-Santy Worm Patches phpBB Flaw


Anti-Santy Worm Patches phpBB Flaw 12/31/2004 12:08 PM

Santy.E worm poses threat to sites badly
coded in PHP


Santy.E worm poses threat to sites badly
coded in PHP
12/27/2004 11:15 AM
The latest version of the Santy worm poses an elevated risk to many Web sites built using the PHP scripting language, and protection of those sites may involve individually recoding them, security experts warned over the weekend.

Google Nukes Santy Worm, But Search
Threat Remains


Google Nukes Santy Worm, But Search
Threat Remains
12/26/2004 10:35 PM
eWeek Dec 27 2004 1:21AM GMT

Santy variants target AOL and Yahoo
Computer worm uses searches to spread


Santy variants target AOL and Yahoo
Computer worm uses searches to spread
12/28/2004 07:25 AM
San Francisco Chronicle Dec 28 2004 11:41AM GMT

Santy and SSL


Santy and SSL 01/06/2005 07:44 PM
Ofer Shezaf (Jan 06 2005)

Santy blues


Santy blues 12/22/2004 01:57 AM
CNET Asia Dec 22 2004 6:19AM GMT

New Santy Mutant Offers 'Help'


New Santy Mutant Offers 'Help' 12/31/2004 04:27 PM
Anti-Santy-Worm V4 attempts to patch vulnerable Web forum software but might cause denial-of-service attacks.

New Santy Variants Spread Beyond Google


New Santy Variants Spread Beyond Google 12/28/2004 11:11 PM
Computer Reseller News Dec 29 2004 2:23AM GMT

Santy variants target AOL and Yahoo


Santy variants target AOL and Yahoo 12/28/2004 09:09 AM
San Francisco Chronicle Dec 28 2004 1:30PM GMT

Dynamically Typed: Santy/Perl.PhpInclude


Dynamically Typed: Santy/Perl.PhpInclude 12/29/2004 09:44 AM
Over on Dynamically Typed today, there's a new posting concerning the latest worm(s) that seem to be going around - Sanity/Pe rl.PhpInclude.

New Santy Mutant Offers 'Help' (Ziff
Davis)


New Santy Mutant Offers 'Help' (Ziff
Davis)
12/31/2004 04:42 PM
Ziff Davis - Anti-Santy-Worm V4 attempts to patch vulnerable Web forum software but might cause denial-of-service attacks.

Security Watch: Internet Bulletin Boards
Join The Santy Generation


Security Watch: Internet Bulletin Boards
Join The Santy Generation
12/28/2004 07:36 PM
ABCNEWS.com Dec 28 2004 10:16PM GMT

The Value of Forums


The Value of Forums 05/26/2004 07:38 PM
?There are literally thousands of online forums that cover a wide range of topics. Forums provide individuals, who share a common interest, with a meeting place for open discussion, and a great gathering spot for ?water cooler? talk. When used properly forums can be an excellent business tool and resource. By providing well thought out, helpful responses posters can develop a reputation as an industry expert. Establishing a reputation within forums will eventually lead to solid business contacts and relationships.?

WQD Forums hit 100


WQD Forums hit 100 08/27/2004 01:34 PM

In December, I announced that I quit drinking. I got a flurry of comments of support. Several of us who had decided to be sober, thought a group blog about quitting drinking would be interesting so we started We Quit Drinking, the blog. Soon, due to some weird Google magic, the blog became the first result for "quit drinking". A wide variety of people who were looking for support and help dropped in and commented. Jonas, who among other things works with addiction as a counselor, decided that a more private space, a message board requiring login might make sense so he created the WQD Forums. He announced today that WQD Forums has hit 100 members and have become a vibrant community of people who are in various stages of sobriety sharing and supporting. Since that day in December, I've received sooo much input and advice. Thank you. Some of it has been very useful and some, frankly, not so helpful. I have been to a few AA meetings and have really enjoyed them. On the other hand, I have not yet passed the first step, "Step One: We admitted we were powerless over alcohol, that our lives had become unmanageable." At the meeting I said, "I think I have a problem, but I don't yet believe that I am powerless or that my life has become unmanagable." The interesting thing is, no one was upset. One AA'er later said, "In AA, we call that 'a quart short'". I think I will still drop into AA meetings because I love the stories and the comfortable atmosphere of sharing, but until I get to Step One somehow, I don't think I can really be a true member. It's been quite a journey hearing the wide variety of opinions about drinking. I've decided on the few advisors and approaches that I think work for me now in helping manage myself. My opinion may change and if I finally believe that I am powerless and my life has become unmanagable, I know I can always count on AA, which I now believe has an incredible power to save people from alcoholism. If you thinking you have a problem or know you have a problem, try dropping by WQD Forums and join us in our emerging community.

Comment - TrackBack

Re: Web Wiz Forums ver. 7.01


Re: Web Wiz Forums ver. 7.01 11/14/2003 05:12 PM
bruce_at_webwizguide.info (Nov 14 2003)

Web Wiz Forums ver. 7.01


Web Wiz Forums ver. 7.01 11/13/2003 05:17 PM
HEX (Nov 13 2003)
Grok Description matches for Santy Worm Defaces Web Forums
GrokA matches for Santy Worm Defaces Web Forums

Santy Worm Defaces Web Forums

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Cisco to Buy
Security Firm
Protego

Microsoft Bloggers
Face Search Spam
Pinch

Cognos Profit Climbs
with Enterprise
Deals

Eclipse Refreshes
Platform for Test,
Performance Tools

Analysts Upbeat on
EMC's Smarts Buy

Mozilla Advances Its
Namesake Suite

Xsan Release Delayed
Next PowerPC To
Support Multiple
OS's?

Couldn't Have Done
It Without You

Switched to iTunes +
iPod

ANN: FeedDemon 1.5
Beta 4

FeedDemon meets The
Beastles

DomainNesteggs.com
Offers Tomorrow’s
Healthcare Domain
Names Today

My girlfriend
flaunts her money

Bad sex or good
irony?

Digital fashion
design ain't as easy
as it looks

Bush's tax overhaul
may be incremental

Back by unpopular
demand

Investigating Ohio
The year in sports
The post-9/11 brain
drain

Oyez, oyez
Buyers' remorse?
The bad apple at the
top of the tree

More revealing than
a wet sari

Surveys say
Verizon, T-Mobile
likely to lead FCC
wireless sale

Orange UK echoes
Vodafone's cautious
approach to 3G
pricing

CSL hedges bets as
3G goes to air:
report

Vodacom launches 3G
phones at no ext

SmarTone starts 3G
services in HK

Service Assurance
for H3G Mobile
Websites

Strategic
Partnership for
i-mode in Russia

Simplified Tests on
3G WCDMA Base
Stations

New F901iC 3G FOMA
Handset

Cellcom RFP for
nationwide 3G
network

iPod uses Bluetooth
to become stereo
remote

NTT DoCoMo aquires
Stake in MontaVista
Linux Software
Company

WRC revs up Web and
mobile coverage

DoCoMo 3G phone
offers global
roaming

Newbie Question:
3660 Bluetooth ?

I mucked up my GPRS
settings!

Mobile companies go
into a tizzy, alarm
bells ring for 3G

Siemens Uses Actix
for UMTS

DoCoMo Invests in
MontaVista

3G: Anything in it
for businesses?

Costs likely to
hamper 3G growth in
SA

3G UMTS PC Modem
Cards to Singapore's
SingTel

Software Tool for 3G
Network Optimisation

NTT DoCoMo to
Acquire Stake in
U.S. Developer of
Linux Software

what is grok?