View Full Version : Worm makes unwelcome visit..
DarrenC
Dec 27th 2004, 10:37 pm
Article from BBC News: http://news.bbc.co.uk/1/hi/technology/4117711.stm
Voyager
Dec 27th 2004, 11:58 pm
I have over eighteen hundred IP addresses null routed because of this worm.
crazyhorse
Dec 28th 2004, 2:02 am
Well not sure whether this worm made a visit to my forum ... but here is the fix to make you less vulnerable http://www.shoutingtalk.com/admin/mods/easymod/php.mod
subnet_rx
Dec 28th 2004, 11:45 am
I was hit by this, very nasty, deleted lots of files.
crazyhorse
Dec 28th 2004, 12:11 pm
Did you have a backup?
Josh
Dec 28th 2004, 2:52 pm
Well not sure whether this worm made a visit to my forum ... but here is the fix to make you less vulnerable http://www.shoutingtalk.com/admin/mods/easymod/php.mod
There are two exploits, there is that one, which the original (not sure about the new varients) doesn't use, and then there is the highlight() exploit, which the wom does use.
The highlight exploit was fixed in 2.0.11, but the other one, which is the unserialze thing that the above patches, is not a phpBB bug, but rather a PHP bug.. so.. that patch is just a workaround. The best thing to do is to get the latest php release, since many many other scripts use that function, but if all you run is phpBB, you may be safe..
Josh
Will.Spencer
Dec 29th 2004, 7:31 am
That link seems to be dead.
Try this one:
http://www.phpbbstyles.com/viewtopic.php?t=1904
crazyhorse
Dec 30th 2004, 1:26 am
There is some more info on this topic on the phpbb forum itself.
There are two things mentioned in there that seem important to do...
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046
vBulletin® v3.6.8, Copyright ©2000-2008, Jelsoft Enterprises Ltd.