Quote:
Originally Posted by Erwin
Always have backups. 
|
There is a new worm that exploits the safe mode file traversal bug in php versions prior to 4.3.10. It uploads files to /tmp and excutes them. This makes the box a zombie. It joins an irc channel and from there the botmaster can control the box and make it do whatever it is he is going to do with all the zombies he is creating.
Upgrade php to the latest version if you haven't done so already. If you are on a shared host make sure to let the isp know about upgrading. There are other vulns in php and will be more worms like this one to exploit the other bugs.