We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Is Our Site at risk?

Having just read an article on ZDNET I wonder is our site at risk from the Santa worm?

The article read:

Net worm using Google to spreadBy Robert Lemos CNET News.com December 21, 2004, 11:01 AM PT

Security Search Viruses and worms Security threats Programming languages Google

A Web worm that identifies potential victims by searching Google is spreading among online bulletin boards using a vulnerable version of the program phpBB, security professionals said on Tuesday.

The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread, according to updated analyses. The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement.

Almost 40,000 sites may have already been infected. Using Microsoft's Search engine to scan for the phrase "NeverEverNoSanity"--part of the defacement text that the Santy worm uses to replace files on infected Web sites--returns nearly 39,000 hits.

"Santy.a is spreading rapidly," antivirus firm Kaspersky stated in a new release published Tuesday. "However, this does not directly affect users. Although the worm infects Web sites, it does not infect computers used to view those sites."

The worm sends Google a specific search request, essentially asking for a list of vulnerable sites. Armed with the list, the worm then attempts to spread to those sites using a PHP request designed to exploit the phpBB bulletin board software.

The worm is the latest twist on using Google as an attack tool, a practice known as Google hacking. It may also be the first time a program used Google to identify victims for an attack.

Around 6 million sites appear to be running the phpBB software, according to a search of Google for the phrase "Powered by phpBB"--an acknowledgment appended to the bottom of any site that uses the software.

"There are tons of these PHP bulletin board installs around," said Johannes Ullrich, chief technology officer of the Internet Storm Center, which tracks online threats. Initial analyses by the ISC had concluded that the flaw exploited by the worm occured in the software that interprets Web pages written scripting language PHP: Hypertext Preprocessor (PHP). That flaw was found last week.

Using Google to determine vulnerable sites is not an academic exercise. The worm does exactly that: Once Santy infects a Web site, it searches Google for other sites running phpBB and then attempts to infect those sites as well.

After it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X," according to Kaspersky. For "X," the worm inserts a number representing how far the current instance of the program is descended from the original worm release. MSN searches have found 24th generations of the worm.

Google did not immediately comment on the worm, but a spokesman did say that the company had seen the information and had started to study the issue.

The response, or lack thereof, frustrated some members of the antivirus community, who believed that the search giant could easily stop the worm by filtering out its search for victims.

"We know exactly which searches to stop," said Mikko Hypponen, research director of antivirus firm F-Secure. "It would be trivial to stop this thing."

Web sites using a vulnerable version of phpBB should upgrade, the phpBB Project site advises.


Anybody know?

Spikey
Use your judgement, and above all, be honest with yourself. :)
I walk with the world & the world walks with me!
I don't make bad choices!!! Other people just fail to see my GENIUS !!!! :D

Comments

  • If by our site you mean the forums here at moneysavingexpert.com then no because it's YaBB that's used here and not phpBB.
    Alex Jones
  • monomer
    monomer Posts: 216 Forumite
    Part of the Furniture Combo Breaker
    I've already seen one such defaced page (not on this site though).

    From the page that I visited, it seems to affect some comment systems used on personal weblogs as well (which I presume are running phpBB).
    "...And I gave that man directions, even though I didn't know the way, 'cause that's the kind of guy I am this week." -- Homer Simpson
  • wirm
    wirm Posts: 5,273 Forumite
    I have noticed this on quite a few sites latly! :-/
  • sra
    sra Posts: 4,673 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    I found this interesting little site the other day: big-boards.com

    While not knowing how accurate the site is, it's interesting to note that of the biggest boards on the web, only two use yabb (click here) which I assume would mean no-one would even bother targeting it.

    On the other hand, look at vbulletin (which we're changing to). If this kind of attack becomes common, guess who the bad guys will want to taget the most
  • monomer
    monomer Posts: 216 Forumite
    Part of the Furniture Combo Breaker
    Google have responded to the worm and is filtering its results so that the worm can't spread any more.

    Reference:
    Google squashes Santy worm (ZDNet)
    "...And I gave that man directions, even though I didn't know the way, 'cause that's the kind of guy I am this week." -- Homer Simpson
  • I think there's a reason only two use YABB based on this sites problems with it ability to handle large amounts of traffic.

    Also interesting to note that in just over 400,000 posts time these forums will be able to join big boards :)
    I found this interesting little site the other day: big-boards.com

    While not knowing how accurate the site is, it's interesting to note that of the biggest boards on the web, only two use yabb (click here) which I assume would mean no-one would even bother targeting it.

    On the other hand, look at vbulletin (which we're changing to). If this kind of attack becomes common, guess who the bad guys will want to taget the most
    Alex Jones
  • sra
    sra Posts: 4,673 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    Also interesting to note that in just over 400,000 posts time these forums will be able to join big boards :)

    noticed that. I suppose total posts will depend on how much of the backed up board is restored :)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.