Gossamer Forum
Home : Products : Links 2.0 : Discussions :

NeverEverNoSanity Webworm

Quote Reply
NeverEverNoSanity Webworm
Hello,

This little devil apparently exposed a vulnerability in phpBB and then envaded my Links 2.0. It defaces all writeable files. In this case, I think the only files it defaced for Links were the index.html files located in each category directory. Can anyone confirm this and/or help me out by giving me an html file I can upload to solve this problem?

Cheers,

Topix
Quote Reply
Re: [Topix] NeverEverNoSanity Webworm In reply to
You mean that it managed to hack into your account, and edit files? phpBB's vunrability (AFAIK) didn't have anything to do with that kinda of attack Unsure

Cheers

Andy (mod)
andy@ultranerds.co.uk
Want to give me something back for my help? Please see my Amazon Wish List
GLinks ULTRA Package | GLinks ULTRA Package PRO
Links SQL Plugins | Website Design and SEO | UltraNerds | ULTRAGLobals Plugin | Pre-Made Template Sets | FREE GLinks Plugins!
Quote Reply
Re: [Andy] NeverEverNoSanity Webworm In reply to
Well, I'm not quite sure how it got in then. It 'defaced' my Level10 hit counter script, Links2, and my phpBB forum all in one shot. I know of a lot of other people it happened to as well and they all run phpBB. People who were on my box all got nailed unless they were running phpBB 2.0.11 and I heard the same for many people who weren't even using my host (Fuitadnet.com).
Below is an example (Links2) of what it does. It leaves your databases in tact but in this case it defaced all html files with the following. This example was taken from index.html in my 'New' directory:


Code:
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>This site is defaced!!!</TITLE>
</HEAD><BODY bgcolor="#000000" text="#FF0000">
<H1>This site is defaced!!!</H1>
<HR>
<ADDRESS><b>NeverEverNoSanity WebWorm generation 22.</b></ADDRESS>
</BODY></HTML>

Last edited by:

Topix: Jan 28, 2005, 12:14 PM