Loans - Bad Credit Mortgages - e Harmony - Homeowner Loans - Myspace Layouts

PDA

View Full Version : Worm makes unwelcome visit..


DarrenC
Dec 27th 2004, 10:37 pm
Article from BBC News: http://news.bbc.co.uk/1/hi/technology/4117711.stm

Voyager
Dec 27th 2004, 11:58 pm
I have over eighteen hundred IP addresses null routed because of this worm.

crazyhorse
Dec 28th 2004, 2:02 am
Well not sure whether this worm made a visit to my forum ... but here is the fix to make you less vulnerable http://www.shoutingtalk.com/admin/mods/easymod/php.mod

subnet_rx
Dec 28th 2004, 11:45 am
I was hit by this, very nasty, deleted lots of files.

crazyhorse
Dec 28th 2004, 12:11 pm
Did you have a backup?

Josh
Dec 28th 2004, 2:52 pm
Well not sure whether this worm made a visit to my forum ... but here is the fix to make you less vulnerable http://www.shoutingtalk.com/admin/mods/easymod/php.mod

There are two exploits, there is that one, which the original (not sure about the new varients) doesn't use, and then there is the highlight() exploit, which the wom does use.

The highlight exploit was fixed in 2.0.11, but the other one, which is the unserialze thing that the above patches, is not a phpBB bug, but rather a PHP bug.. so.. that patch is just a workaround. The best thing to do is to get the latest php release, since many many other scripts use that function, but if all you run is phpBB, you may be safe..

Josh

Will.Spencer
Dec 29th 2004, 7:31 am
That link seems to be dead.

Try this one:

http://www.phpbbstyles.com/viewtopic.php?t=1904

crazyhorse
Dec 30th 2004, 1:26 am
There is some more info on this topic on the phpbb forum itself.
There are two things mentioned in there that seem important to do...

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046