stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Santy Worm Varients Spreading







Santy Worm Varients Spreading

Santy Worm Varients Spreading 12/28/2004 07:14 PM

As we reported last week, Google had been used by the "Santy.A" worm to infect websites using vulnerable versions of phpBB. Google has since disallowed such search attempts by the worm, by simply not listing vulnerable sites in their search results.

Variants are now attempting to exploit search engines offered by Yahoo and AOL, targeting sites running versions of phpBB prior to version 2.0.11. Some variants of the worm damage sites using poorly coded php instances of include() and require(). AOL claims that they are now unaffected, but Yahoo has yet to comment on their security status.

Santy deletes content from effected php-based sites, and replaces it with information found within the worm itself. Luckily this worm is not communicable to computers who visit effected sites. Sites using older versions of phpBB should update immediately, and some sites utilizing php may have to be rewritten all together.

View: Google's Response @ F-Secure Virus Lab Blog

Read full story...




This is a GrokNews Entry: (what is grok?)





Similar Items

Santy Worm Varients Spreading

Grok Headline matches for Santy Worm Varients Spreading

Re: New Santy-Worm attacks *all*
PHP-skripts ( Santy.c ? )


Re: New Santy-Worm attacks *all*
PHP-skripts ( Santy.c ? )
12/25/2004 05:08 PM
K-OTiK Security (Dec 25 2004)

The Santy worm mutates


The Santy worm mutates 12/28/2004 05:37 PM
TechSpot Dec 28 2004 9:42PM GMT

Google blocks Web worm Santy.A


Google blocks Web worm Santy.A 12/29/2004 08:44 PM
The Hindu Business Line Dec 30 2004 12:40AM GMT

Santy worm now targets Yahoo and AOL


Santy worm now targets Yahoo and AOL 12/28/2004 09:28 PM
Pravda Dec 29 2004 1:50AM GMT

Santy worm Targets AOL Yahoo


Santy worm Targets AOL Yahoo 12/28/2004 11:11 PM
WebProNews Dec 29 2004 3:43AM GMT

New Santy-Worm attacks *all* PHP-skripts


New Santy-Worm attacks *all* PHP-skripts 12/25/2004 05:09 PM
Juergen Schmidt (Dec 25 2004)

Anti-Santy worm on the prowl


Anti-Santy worm on the prowl 12/31/2004 12:32 PM
ZDNet Dec 31 2004 5:10PM GMT

New Santy Worm Threatens More Sites


New Santy Worm Threatens More Sites 12/27/2004 03:53 PM
Techzonez Dec 27 2004 7:52PM GMT

Anti-Santy worm spreads


Anti-Santy worm spreads 12/31/2004 09:02 AM
ZDNet UK Dec 31 2004 1:20PM GMT

New worm, Santy, using Google to spread


New worm, Santy, using Google to spread 12/22/2004 01:52 AM
Antivirus companies are warning Internet users about a fast-spreading new worm that infects Web servers running a popular package of online bulletin board software, and uses the Google search engine to find vulnerable servers to infect.

Google smacks down Santy worm


Google smacks down Santy worm 12/24/2004 12:27 PM
Google said it was blocking searches generated by a new worm, Santy.A, which were being used to find and infect vulnerable computers on the Internet.

Santy Worm Defaces Web Forums


Santy Worm Defaces Web Forums 12/22/2004 01:35 AM
The Internet worm is squirming through Web servers that are running unpatched versions of the popular phpBB Web forum software. Santy uses Google search to randomly find sites running phpBB and then overwrites files.

New worm, Santy.A, using Google to
spread


New worm, Santy.A, using Google to
spread
12/22/2004 12:58 AM
Antivirus companies are warning Internet users of a new, fast-spreading worm that uses the Google search engine to infect Web servers running a popular package of online bulletin board software.

Santy Worm Hits AOL, Yahoo


Santy Worm Hits AOL, Yahoo 12/28/2004 12:49 PM
Enterprise Security Today Dec 28 2004 4:49PM GMT

Google squashes Santy worm


Google squashes Santy worm 12/22/2004 01:41 AM
Search firm shuts off ability of worm--which searched for victims via Google--to replicate.

Santy worm defaces thousands of sites


Santy worm defaces thousands of sites 12/22/2004 01:07 AM

Other News: Santy worm takes new tack


Other News: Santy worm takes new tack 12/28/2004 03:33 AM
The Santy worm, which originally used Google searches to locate vulnerable phpBB installations, has now mutated to use AOL and Yahoo instead.

BBC: Santy Worm Makes Unwelcome Visit


BBC: Santy Worm Makes Unwelcome Visit 12/24/2004 01:04 PM
"Thousands of website bulletin boards have been defaced by a virus that used Google to spread across the net..."

Google stops spread of Santy worm


Google stops spread of Santy worm 12/24/2004 12:36 PM

Google Becomes Unwitting Abettor for
Santy Worm


Google Becomes Unwitting Abettor for
Santy Worm
12/22/2004 01:44 AM

The new Santy worm uses the Google search engine to find vulnerable websites and then defaces the sites' bulletin boards. The worm, formally named Net-Worm.Perl.Santy, attacks website bulletin boards (Internet forums or message centers) running versions of the popular phpBB bulletin board application. The worm exploits a known security vulnerability in early releases of the phpBB application, defacing the contents of the bulletin board.


Santy PHP Worm Variant With 50 Exploits
Discovered


Santy PHP Worm Variant With 50 Exploits
Discovered
01/02/2005 02:05 PM

Anti-Santy Worm Patches phpBB Flaw


Anti-Santy Worm Patches phpBB Flaw 12/31/2004 12:08 PM

Net-Worm.Perl.Santy.a threatens Internet
forums


Net-Worm.Perl.Santy.a threatens Internet
forums
12/22/2004 01:17 AM

Google Nukes Santy Worm, But Threat
Remains


Google Nukes Santy Worm, But Threat
Remains
12/24/2004 12:17 PM
Extreme Tech Dec 24 2004 3:33PM GMT

Santy.E worm poses threat to sites badly
coded in PHP


Santy.E worm poses threat to sites badly
coded in PHP
12/27/2004 11:15 AM
The latest version of the Santy worm poses an elevated risk to many Web sites built using the PHP scripting language, and protection of those sites may involve individually recoding them, security experts warned over the weekend.

Google Nukes Santy Worm, But Search
Threat Remains


Google Nukes Santy Worm, But Search
Threat Remains
12/26/2004 10:35 PM
eWeek Dec 27 2004 1:21AM GMT

Santy variants target AOL and Yahoo
Computer worm uses searches to spread


Santy variants target AOL and Yahoo
Computer worm uses searches to spread
12/28/2004 07:25 AM
San Francisco Chronicle Dec 28 2004 11:41AM GMT

AIM worm spreading around?


AIM worm spreading around? 02/12/2004 01:25 AM
Moshe Jacobson (Feb 11 2004)

RE: AIM worm spreading around?


RE: AIM worm spreading around? 02/13/2004 05:27 AM
Tim Walraven (Feb 12 2004)

New internet worm spreading


New internet worm spreading 02/17/2004 02:34 PM
Townsville Bulletin Feb 17 2004 6:33PM GMT

New Lovegate worm is spreading


New Lovegate worm is spreading 07/06/2004 10:03 AM

Re: New Varient Of Irc Worm Spreading


Re: New Varient Of Irc Worm Spreading 11/01/2003 12:56 PM
bob (Oct 31 2003)

New Worm Spreading Through E-Mail


New Worm Spreading Through E-Mail 03/06/2004 01:53 AM
A new computer worm dubbed "Netsky-D" was clogging e-mail systems around the world after emerging on Monday, a security expert said.

New Varient Of Irc Worm Spreading


New Varient Of Irc Worm Spreading 10/31/2003 08:29 PM
Craig Holmes (Oct 31 2003)

"new worm that is spreading through MSN
Messenger"


"new worm that is spreading through MSN
Messenger"
01/04/2004 03:53 AM

Death penalty worm spreading


Death penalty worm spreading 06/15/2004 11:54 AM
Computer Weekly Jun 15 2004 3:21PM GMT

McAfee: New Lovegate worm spreading


McAfee: New Lovegate worm spreading 07/02/2004 04:33 PM
The latest version of the Lovegate worm appears to be more successful than some of its predecessors at infecting vulnerable computers.

Sasser worm begins spreading


Sasser worm begins spreading 05/01/2004 11:41 AM
ZDNet May 1 2004 3:38PM GMT

New Worm Is Spreading Rapidly Via E-Mail


New Worm Is Spreading Rapidly Via E-Mail 01/28/2004 11:24 AM
New York Times Jan 28 2004 4:07PM GMT
Grok Description matches for Santy Worm Varients Spreading
GrokA matches for Santy Worm Varients Spreading

Santy Worm Varients Spreading

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Optimize Your
DeliciousExport

Duffield resigns
from PeopleSoft

Cabir cell phone
threat worsens

Apple CEO Leads Bay
Area in Salary (AP)

PeopleSoft CEO
Resigns Ahead of
Takeover (AP)

PeopleSoft CEO Quits
as Oracle Deal Nears
(Reuters)

Navy SEALs Sue
Associated Press
Over Iraq Photos
(Reuters)

Dave Duffield
Redefines Long Term
As Less Than Three
Months

Latest Linux Kernel
Hits

Apple CEO
highest-paid
executive in Bay
Area

Update: Amazon says
holiday sales beat
last year

Two new Cabir mobile
phone worms spotted

Feds to probe
airline delays over
holiday weekend

U.N.: Warning
systems vital to
slash disaster tolls

Disease 'could swamp
wave zones'

NASA Finishes
Redesigned Shuttle
Fuel Tank (Reuters)

ADRA International
American Friends
Service Committee

Red Cross Red
Crescent

operation usa index
International
Medical Corps

Walmart.com - How
Walmart Is
Destroying America
And The World: And
What You Can Do
About It

CNN.com - Donations
to tsunami relief
'generous,' U.N.
says - Dec 28, 2004

Getting Firefox to
Live Bookmark Your
RSS Feed

Will a Hacker Crash
your Cell Phone?

Sample the Future
MapEditor 0.0.6
Jomic 0.9.5
Namistai 1.17.1
phpPeanuts 1.1 beta
1 portable 1

Mesa 6.2.1
Linux Test Project
20041203

Management Objects
for Your Assets
Suite 0.13.1

db4o 4.1
(Development)

Access_user Class
1.6

Motorola V635
RandomMp3Copy
ScopeGrab32 for
ScopeMeter
oscilloscopes

MXOEmu
Auton Document
Management System

Mordor -
Resurrection

Bay area message
board costs papers
millions

PeopleSoft CEO
abandons ship

Susan Sontag, Writer
and Social Critic,
Dies at 71

In Indonesia,
'Devastation and
Death Beyond Belief'

Netcat v1.11 For
Windows , New fixed
version

Independent dealers
press on with
lawsuit against
Apple

Profits at overseas
subsidiaries soar in
2003

Tarantella Ships
Updated Terminal
Software

U.S. More Than
Doubles Tsunami Aid,
Promises More

what is grok?