Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

New worm, Santy.A, using Google to spread

It infects Web servers running a software package called phpBB

December 21, 2004 12:00 PM ET

IDG News Service - Antivirus companies are warning Internet users about a new, fast-spreading worm that infects Web servers running a popular package of online bulletin board software and uses the Google search engine to find vulnerable servers to infect.
The worm, dubbed Santy.A, uses a vulnerability in a popular free software package called phpBB to spread across the Internet, infecting computer servers that host online bulletin boards and defacing those sites with the words "This site is defaced!!! NeverEverNoSanity WebWorm."
A Google Inc. spokesman said in an e-mail that the company is looking into reports about Santy.A.
The worm doesn't affect individual computer users but infects Web servers that are hosting online bulletin boards.
Santy.A was first spotted early this morning in the U.S., according to Mikko Hypponen, manager of antivirus research at F-Secure Corp. in Helsinki, Finland.
The worm takes advantage of a critical software vulnerability in the phpBB open-source software, which is widely used to create and maintain online bulletin boards. Although antivirus companies are still analyzing the worm, it appears to use a vulnerability in the PHP scripting language that was recently patched, according to Alexey Zernov, a spokesman for antivirus company Kaspersky Labs Ltd. in Moscow. PhpBB and other common software packages are written using PHP.
Once Santy infects servers running the phpBB software, it scans directories on the infected site and overwrites files with the extensions .htm, .php, .asp, .shtm, .jsp and .phtm with the text "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation," according to an alert from Kaspersky Labs.
The worm also launches a search on the Google search engine for URLs that use a special string, viewtopic.php, which is common to bulletin boards written using the phpBB software, Hypponen said.
The worm's reliance on Google could be its downfall, however. If the search engine company can block the search text used by Santy.A, it would stop the worm from spreading, he said.
Hypponen said he was trying to contact Google to get the company's help in blocking Santy.A requests.
Antivirus experts don't believe Santy.A deposits Trojan horse programs or other malicious code on the systems it infects. Also, Santy doesn't affect individual computer users, unless they are hosting a bulletin board from their computer that uses the phpBB software, antivirus experts said.
However, Santy.A could act as a road map for malicious hackers who are looking for vulnerable computers to exploit, Hypponen said.
Both F-Secure and Kaspersky Labs posted updated antivirus definitions that can spot the Santy.A worm and advised customers toupdate their antivirus software as soon as possible.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

Case Study: The Ritz London
Discover how the superior capabilities of Webroot E-mail Security SaaS allows user to focus on their principal tasks instead of wasting their time...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Case Study: Richmond Ambulance Authority (RAA)
In this case study, find out how Webroot Web Security SaaS delivers the proactive web security RAA needs....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Can Heuristic Technology Help Your Company Fight Viruses?
(Source: MessageLabs - now part of Symantec) In the face of today's increasingly sophisticated malware, using multiple layers of email and web protection...  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....