Author Topic: Warning about virus targeting phbb boards  (Read 2920 times)

0 Members and 1 Guest are viewing this topic.

Offline hikaru_maxwell

  • Catgirl
  • ****
  • Posts: 638
Warning about virus targeting phbb boards
« on: December 22, 2004, 08:19:35 am »
This virus hit one of the other forums I belong to...which is powered by the same software as kumoricon forum...it went through and wiped out the forum and the connected site, so I felt it was a good idea to warn you guys about it....

'Santy' spread quickly, but targets are limited

By Bob Sullivan
Technology correspondent
MSNBC
Updated: 3:19 p.m. ET Dec. 21, 2004

A new computer worm that attacks bulletin board services spread silently and quickly around the Internet Tuesday, infecting at least 38,000 systems within a few hours, experts said. The worm does not attack home computers, but consumers might encounter its effects.  Bulletin boards that are infected will show a simple text message: "This site is defaced!!! This site is defaced!!! NeverEverNoSanity."

advertisement
 
The worm only attacks widely used message board software called PHP Bulletin Board. Other than displaying the text message, it does nothing malicious to infected computers, according to antivirus firm Kaspersky Labs. Because it spread rather quickly Tuesday morning, F-Secure Corp. issued an alert about Santy.

"This is spreading very rapidly," said Ken Dunham, director of malicious code research at iDefense Inc.  

As a network-based worm, the malicious program is capable of making the rounds quickly without any user interaction, such as clicking on an e-mail attachment. In that way, Santy is similar to the Code Red or Nimda attacks, but the list of potentially vulnerable computers is far more limited that those attacks, said virus researcher Oliver Friedrichs of Symantec Corp.

Santy searches for its digital victims using the Google search engine, Dunham said. The malicious program searches for a particular string of text to find computers running the vulnerable bulletin board software, then attacks them.

"It only takes so long to Google and deface," he said.

Friedrichs said attacks that take advantage of the powerful Google search engine are becoming more common. Earlier this year, the MyDoom computer virus temporarily disabled Google by harvesting e-mail addresses through the service.

"It's not the first time we've seen a threat leveraging Google," he said. "It's extremely attractive to worm (author) who relies on gathering information like e-mail addresses. ... this is a trend we expect to continue."

Another intriguing Santy trick: The worm brags about infecting "generations" of computers.  Worms spread exponentially. The first infected computer may attack a dozen or more machines, each of which in turn attacks another dozen, and so on.  Even after just four or five levels -- like generations in a family tree -- the attack is widespread.  

Santy keeps track of its family tree, announcing which generation has arrived on an infected computer.  Searches for infected machines at 3 p.m. ET Tuesday showed the worm had already reached generation 24.

"It does appear to be continuing to spread," Dunham said.

 © 2004 MSNBC Interactive


^japankore.net (my other forum) was hit by generation 8....

~*~Member of Cannot Unsee~*~

Offline EvilMonkey

  • Founder
  • Catgirl
  • ****
  • Posts: 580
    • http://evilmonkeysean.livejournal.com
Warning about virus targeting phbb boards
« Reply #1 on: December 22, 2004, 11:14:02 am »
It's actually a vunerability in the PHP software on unpatched servers.  I checked with our host, and they made sure they patched their PHP within the hour that the patch was available.  We should be safe.

Sean
~Sean Larson~

Offline hikaru_maxwell

  • Catgirl
  • ****
  • Posts: 638
Warning about virus targeting phbb boards
« Reply #2 on: December 22, 2004, 12:07:49 pm »
Okay, that's good to know.....I should tell my other hosts that....I don't think they knew about the patch.

~*~Member of Cannot Unsee~*~

Offline Irnogs

  • Chibi
  • ***
  • Posts: 335
Warning about virus targeting phbb boards
« Reply #3 on: December 22, 2004, 01:11:36 pm »
yeah, my web host was nice and sent me an email about that. They also told me that the patch would work and even offered to do it for me if I wasn't able to... :) I'm really liking my new host...