Vienna Symphonic Library Forum
Forum Statistics

198,766 users have contributed to 43,133 threads and 258,838 posts.

In the past 24 hours, we have 2 new thread(s), 14 new post(s) and 59 new user(s).

  • Admin Alert: phpbb forum net worm spread by Google

    Hi folks,

    My name is Frederick Russ, owner of VI Control Forum - a phpBB site. Currently we're in the process of rebuilding the site - luckily the database is still intact. Please - the alert here is serious. I love the VSL forum and do not want anything happening to it. It almost happened to me. In order to avoid anything happening to the forum here, it is imperative that the phpBB version at VSL be updated to version 2.0.11 asap.

    A Web worm that identifies potential victims by searching Google is spreading among online bulletin boards using a vulnerable version of the program phpBB, security professionals said on Tuesday.

    An important distinction is that it is not a phpBB problem - it is a PHP problem which can be exploited through phpBB software lower than version 2.0.11

    The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread, according to updated analyses. The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement.

    Our programmer informed us that at least 2,000 phpBB sites have already been defaced. Almost 40,000 sites may have already been infected. Using Microsoft's Search engine to scan for the phrase "NeverEverNoSanity"--part of the defacement text that the Santy worm uses to replace files on infected Web sites--returns nearly 39,000 hits.

    "Santy.a is spreading rapidly," antivirus firm Kaspersky stated in a new release published Tuesday. "However, this does not directly affect users. Although the worm infects Web sites, it does not infect computers used to view those sites."

    The worm sends Google a specific search request, essentially asking for a list of vulnerable sites. Armed with the list, the worm then attempts to spread to those sites using a PHP request designed to exploit the phpBB bulletin board software.

    The worm is the latest twist on using Google as an attack tool, a practice known as Google hacking. It may also be the first time a program used Google to identify victims for an attack.

    A search of Google for the phrase "Powered by phpBB"--an acknowledgment appended to the bottom of any site that uses the software--returned 6 million hits, an indication of the popularity of phpBB. The actual number of sites is likely much lower, since the acknowledgement is appended to multiple pages on a single bulletin board site.

    "There are tons of these PHP bulletin board installs around," said Johannes Ullrich, chief technology officer of the Internet Storm Center, which tracks online threats. Initial analyses by the ISC had concluded that the flaw exploited by the worm occured in the software that interprets Web pages written scripting language PHP: Hypertext Preprocessor (PHP). That flaw was found last week.

    Using Google to determine vulnerable sites is not an academic exercise. The worm does exactly that: Once Santy infects a Web site, it searches Google for other sites running phpBB and then attempts to infect those sites as well.

    After it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X," according to Kaspersky. For "X," the worm inserts a number representing how far the current instance of the program is descended from the original worm release. MSN searches have found 24th generations of the worm.

    Google did not immediately comment on the worm, but a spokesman did say that the company had seen the information and had started to study the issue.

    A way to avoid this is to update the forum software version to 2.0.11 as soon as possible.

    Sincerely,

    Frederick Russ

  • last edited
    last edited
    We finally got our phpBB composers forum back online after a long wait of rebuilding the site from a scheduled backup:

    V.I. Control

    The exploitation of the weakness in earlier versions of PHP via earlier versions of phpBB is serious. I do not want to see VSL forum affected. Please upgrade to phpBB version 2.0.11 as soon as possible.