Amaz0ns Forum
Nov 21, 2009, 09:48 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?
Login with username, password and session length
News: Some boards are only visible to users who are logged in and have more than 20 posts.
 
   Home   Help Search Calendar Login Register  
Pages: [1]
  Print  
Author Topic: Funny thing...  (Read 1861 times)
0 Members and 1 Guest are viewing this topic.
Lingster
Amaz0ns BSD
Administrator
Site Superhero
*****
Gender: Male
Posts: 2113


mightylingster
View Profile WWW
« on: Dec 28, 2004, 03:06 PM »

A few months ago someone managed to insert a line of code into a page at Transvigor.  It made me really paranoid about security, andn so I've been very good at installing new updates for both Wordpress and phpBB.  She Grew! runs on the latter.  

Then this morning:
Quote
The newest version of the Santy Worm, Santy.e, is threatening more web sites which use PHP scripting to produce dynamically database generated pages. The Santy Worm first surfaced last week, targeting sites which use the phpBB bulletin board/forum service. Santy was using Google as its springboard to identify such phpBB powered sites. The Perl/Santy-A worm (also known as Santy) exploited a vulnerability in a piece of software often used to provide discussion forums and bulletin boards on the web, phpBB.
I think we're OK.
Logged

random101
Guest
« Reply #1 on: Dec 30, 2004, 05:53 PM »

Is this something similar to what appears to have happened to Wreck's message board?

The NeverEverSanity WebWorm Generation 13 (or something?) seems to have done something evil to it.

Anyone know anything about this at all?
Logged
Lingster
Amaz0ns BSD
Administrator
Site Superhero
*****
Gender: Male
Posts: 2113


mightylingster
View Profile WWW
« Reply #2 on: Dec 30, 2004, 06:12 PM »

Quote from: random101
Is this something similar to what appears to have happened to Wreck's message board?

The NeverEverSanity WebWorm Generation 13 (or something?) seems to have done something evil to it.

Anyone know anything about this at all?


Well, if it's a worm then it's similar to what I've been cautious about.  What BB is he running?  Sometimes one coder will take an existing worm, trojan script or virus and then simply alter it a bit, change the name and set it loose again.  

The way these things work is that they cross-script themselves onto the server, and then they use the server to do web searches for other servers running the same application suite that the worm used to get onto the first one.  In my case it's phpBB v2.  The phpBB people put out a fix in August or so, and then another in October and another a few weeks ago.  The first fix was sufficient, really, but they've made the code pretty much airtight since then.
Logged

dcmatthews
Global Moderator
Site Superhero
*****
Gender: Male
Posts: 1204


I'll be marching around in gold pants in no time!


View Profile WWW
« Reply #3 on: Dec 31, 2004, 10:43 PM »

Hackers and virus coders must die.

Slowly and painfully.

And I'm not joking.

Hate to have my first post on this board be such a downer, but there are few people I hate more in this world than these bastards who have no conscience whatsoever, whose idea of "fun" is to randomly and capriciously destroy someone else's hard work, just because they can.
Logged

"Ladies in skimpy sci-fi costumes? That sounds like everything I wanna be a part of!" - Strong Bad
Lingster
Amaz0ns BSD
Administrator
Site Superhero
*****
Gender: Male
Posts: 2113


mightylingster
View Profile WWW
« Reply #4 on: Dec 31, 2004, 11:42 PM »

Quote from: dcmatthews
Hackers and virus coders must die.

Slowly and painfully.

And I'm not joking.

Hate to have my first post on this board be such a downer, but there are few people I hate more in this world than these bastards who have no conscience whatsoever, whose idea of "fun" is to randomly and capriciously destroy someone else's hard work, just because they can.


They're the evolutionary process, Dave.  Without these kinds of challenges, OS security and industry standards and practices wouldn't improve, and would be vulnerable to a person with truly malicious and criminal motives.  

If you run a site, part of the responsiblity of that is making sure you follow and install updates.  And updating server code isn't always that easy - it assumes a much higher level of competence than updating run of the mill consumer software.
Logged

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
RocketTheme Joomla Templates