Impact of worm targeting Mambo CMS low, say researchers
Mare.D targets Mambo CMS and PHP XML-RPC
February 21, 2006 12:00 PM ETIDG News Service -
F-Secure Corp. is warning of a network worm that targets vulnerabilities in the Mambo Content Management System (CMS) and PHP XML-RPC, a library of code for PHP programmers that allows procedures to run between computers with different operating systems.
F-Secure calls the worm Mare.D, saying it installs several backdoors on a compromised system. The worm scans random hosts for those running vulnerable installations of the Mambo open source Web site content management system or the PHP XML-RPC library.
Two of the backdoors -- "cb" and "ping.txt" -- are connectback shell backdoors that connected to a remote host via port 8080, F-Secure said. The third is controlled by IRC (Internet Relay Chat) and written in the Perl language. The main component of the worm listens on UDP (User Datagram Protocol) port 27015 for commands, F-Secure said.
Secunia, which also issued an advisory, said the vulnerability affects Version 1.1 of PHP XML-RPC and prior versions. Its advisory recommended upgrading PHP XML-RPC to Version 1.1.1.
Mambo wrote on its Web site that it has issued fixes for versions 4.5.3 and 4.5.3h. Those fixes can be downloaded from Mambo's Web site. It also recommended that users upgrade their software if they have a version earlier than 4.5.3.
So far, it doesn't appear many users have been affected. Graham Cluley, a senior technology consultant with Sophos PLC, said the company has not heard concerns from its customers over the worm.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
