phpBB users, worm spreading

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Can we get a sticky? I'm sure there are a lot of people here using phpBB.
 

simms

Diamond Member
Sep 21, 2001
8,211
0
0
SPCR got hit by this... phpBB is being hit badly with all these exploits.
 

fergiboy

Senior member
Mar 10, 2000
328
0
0
I think this is a problem with phpBB and not a problem with PHP itself. Seems like the people over at phpBB have a big mess on their hands. I have always been a big advocate of PHP but this worm shows why PHP can never be used in high priority applications. PHP allows the programmer too much freedom.

More info
 

DeviousTrap

Diamond Member
Jul 19, 2002
4,841
0
71
I'm wondering what my users will think if I automatically update all phpbb installations on the server
 

Mr N8

Diamond Member
Dec 3, 2001
8,793
0
76
If you haven't been hit yet, your lucky. I think this was exploited, starting the last week of November.

Edit:
Nevermind, just a similar problem. Carry on.
 

Conky

Lifer
May 9, 2001
10,709
0
0
Originally posted by: DeviousTrap
I'm wondering what my users will think if I automatically update all phpbb installations on the server

Well, it will blow out their hacks and other added templates and cause an error if they have the default style set to one of those added templates.

I just updated a client/friends phpbb for him and that's what I ran into.

 

olds

Elite Member
Mar 3, 2000
50,111
774
126
Can't upgrade....
phpBB 2.0.11 Setup
We are upgrading in /home/oldsmobo/public_html/forums... Upgrade script is missing. Upgrade failed, you may have reached your disk quota!
 

DeviousTrap

Diamond Member
Jul 19, 2002
4,841
0
71
Originally posted by: Crazyfool
Originally posted by: DeviousTrap
I'm wondering what my users will think if I automatically update all phpbb installations on the server

Well, it will blow out their hacks and other added templates and cause an error if they have the default style set to one of those added templates.

I just updated a client/friends phpbb for him and that's what I ran into.

Yup, just found that out after some research. I also found that its not really a danger to the server security in general so I'll send out a message to clients and let them deal with it themselves.
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Originally posted by: DeviousTrap
Originally posted by: Crazyfool
Originally posted by: DeviousTrap
I'm wondering what my users will think if I automatically update all phpbb installations on the server

Well, it will blow out their hacks and other added templates and cause an error if they have the default style set to one of those added templates.

I just updated a client/friends phpbb for him and that's what I ran into.

Yup, just found that out after some research. I also found that its not really a danger to the server security in general so I'll send out a message to clients and let them deal with it themselves.

What if you just installed the patches rather than upgrading the whole board?
 

DeviousTrap

Diamond Member
Jul 19, 2002
4,841
0
71
Originally posted by: SagaLore
Originally posted by: DeviousTrap
Originally posted by: Crazyfool
Originally posted by: DeviousTrap
I'm wondering what my users will think if I automatically update all phpbb installations on the server

Well, it will blow out their hacks and other added templates and cause an error if they have the default style set to one of those added templates.

I just updated a client/friends phpbb for him and that's what I ran into.

Yup, just found that out after some research. I also found that its not really a danger to the server security in general so I'll send out a message to clients and let them deal with it themselves.

What if you just installed the patches rather than upgrading the whole board?

I have about 20 installations of phpbb per server and I won't manually patch them, the only other option is to have cPanel upgrade them automatically and I have no clue how that would turn out.
 

randal

Golden Member
Jun 3, 2001
1,890
0
71
Originally posted by: DP
i guess this is what happened to my css clan site? here

Nope, that's a separate worm having to do with Apache permissions. Couple clients got hit by that last night - replaces all yer php & html files with the defacement notice without leaving a backup :-(

It's not a system-affecting thing from what I've seen so far, though. And it doesn't mess with any dbs/otherdata/etc.

edit - Whoops, it is related - just a different generation of the same worm/author.
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
By now most of you have probably seen the reports on the santy.a worm that used a vulnerability in PHP (or PHPBB, some argument there).
This was a particularly destructive worm to those sites that were affected.

This particular worm made use of Google search to identify potential targets. The number of queries generated by this worm was small enough to be down in the noise relative to the normal activity. We were finally notified early Tuesday and by late afternoon we had begun blocking the worm's search queries. The worm should have started dying off almost immediately.

Stephen
--
#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#
Name Removed - Information Security Officer - Removed@google.com
Google, Inc. 1600 Amphitheatre Parkway, Mountain View, CA 94043
Phone: +Removed Fax: +Removed

The church is near, but the road is icy.
The bar is far away, but I will walk carefully. -- Russian Proverb


-+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |