[Full-Disclosure] Possible apache2/php 4.3.9 worm

Ron Brogden domains at islandnet.com
Tue Dec 21 18:43:38 GMT 2004


On December 21, 2004 07:32, Alex Schultz wrote:
> Some of the sites I administer were alledgedly hit by a worm last night.
> It overwrote all .php/.html files that were owner writable and owned by
> apache.  
> <ADDRESS><b>NeverEverNoSanity WebWorm generation 17.</b></ADDRESS> 

Looks like this is the fallout from a recent phpBB hole:

http://www.pcpro.co.uk/news/67505/santya-sparks-messageboard-infection-epidemic.html

Cheers



Full-Disclosure is hosted and sponsored by Secunia.