Skip to content

Biting the hand that feeds IT

The Register ®

Security:


[Print][Mobile][Alerts]

Santy worm defaces thousands of sites

PHP exploit

Published Tuesday 21st December 2004 23:38 GMT

A worm which attacks web servers running the popular phpBB discussion forum software to deface vulnerable systems spread widely across the net today.

The Santy worm searches for vulnerable forum sites using Google. When a suitable target is found, Santy uses a remote exploit to gain access and deface it before resuming its scanning activity. Content on defaced sites is replaced by the following text string.

"This site is defaced!!!" NeverEverNoSanity

Apart from defacing infected sites with this text, the worm has no payload. It will not infect PC used to view infected sites. F-Secure, the Finnish anti-virus firmm estimates there more than one million sites use the vulnerable phpBB software, of which tens of thousands have already been defaced. Users of phpBB are advised to update to version 2.0.11. ®

Related stories

Bofra exploit tied to 'massive botnet'
Son of Code Red is born
IIS worm made to packet Whitehouse.gov
Nokia prefers Python to Perl for smartphone scripting
Your Perl and PHP problems solved

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

Solution Brief: Reduce Energy Costs

Energy consumption has become a big issue. Dramatically increase server utilization and significantly reduce energy costs through Virtualization..
whitepaper title

Search Engine Link Spam

Spammers are constantly finding new, creative ways to attack your network. Learn how search engine links are the latest weapon of choice.
Whitepapers Jobs

Top 20 storiesAll The Week’s HeadlinesArchiveSearch