A new worm that is wreaking havoc on websites uses the popular Google search to hunt down its potential victims. It infects sites running the popular phpBB discussion forum software - a package used to create Web forums.
Termed Net-Worm.Perl.Santy.a., the worm has been detected by Kaspersky Lab, a developer of content management systems. Though the worm is spreading rapidly, it however, does not directly affect end users - it affects only Web servers.
According to the company, it creates a specially formulated Google search request, which results in a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure, which will trigger the vulnerability to these sites.
Once the attacked server processes the request, the worm will penetrate the site, gaining control over the resource. It then repeats this routine.
After gaining control over a site, it scans all directories on the infected site. All files with the extensions .htm, .php, .asp, .shtm, .jsp and phtm will be overwritten with the text 'This site is defaced!!! NeverEverNoSanity WebWorm generation'.
Apart from defacing infected sites with this text, the worm has no payload. It will not infect machines, which are used to view infected sites, claims the company.
Kaspersky Lab recommends that all users of phpBB should upgrade to version 2.0.11 to prevent their sites from being defaced
-------------------------------------------------
بچه ها حتماْ دقت كنيد .
Termed Net-Worm.Perl.Santy.a., the worm has been detected by Kaspersky Lab, a developer of content management systems. Though the worm is spreading rapidly, it however, does not directly affect end users - it affects only Web servers.
According to the company, it creates a specially formulated Google search request, which results in a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure, which will trigger the vulnerability to these sites.
Once the attacked server processes the request, the worm will penetrate the site, gaining control over the resource. It then repeats this routine.
After gaining control over a site, it scans all directories on the infected site. All files with the extensions .htm, .php, .asp, .shtm, .jsp and phtm will be overwritten with the text 'This site is defaced!!! NeverEverNoSanity WebWorm generation'.
Apart from defacing infected sites with this text, the worm has no payload. It will not infect machines, which are used to view infected sites, claims the company.
Kaspersky Lab recommends that all users of phpBB should upgrade to version 2.0.11 to prevent their sites from being defaced
-------------------------------------------------
بچه ها حتماْ دقت كنيد .