B Fly
22/12/2004, 19h59
A titre d'info pour administrateurs de Forum phpBB
Les Versions B et C du ver SANTY pouvant attaquer les serveurs de forums utilisants phpBB sont actuellement lâchés lousses ...
Plus virulents que la version A
Note - Aucun danger pour les utilisateurs du forum
Lundi 27 décembre 2004
New Variant of Santy Worm Spreads
Latest worm poses a risk to many Web sites using the PHP scripting language.
Peter Sayer, IDG News Service
Monday, December 27, 2004
The latest version of the Santy worm poses an elevated risk to many Web sites built using the PHP scripting language, security experts warn. Protecting those sites may involve individually recoding them, those security experts say.
Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software. However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warn.
Santy.C and Santy.E behave so differently from Santy.A that the K-OTik is renaming the worm PhpInclude.Worm in its advisories, the company says. The worm doesn't exploit the vulnerabilities in phpBB targeted by its predecessor, instead aiming for a wider range of common programming errors in PHP Web pages.
It uses search engines including Google, Yahoo, and AOL to identify exploitable Web pages written in PHP which use the functions "include()" and "require()" in an insecure manner, K-OTik says.
Embedded Contents
These functions can be used to embed the contents of a file within a Web page. If the site designer used them without sufficient checking of the parameters passed to the function, then an attacker could exploit them to incorporate an arbitrary file in the Web page, rather than the limited range presumably intended by the site designer. From there, depending on the configuration of the Web server, the attacker could move on to take control of the entire machine, K-OTik warns.
To prevent these attacks, it may be necessary to recode the site to use the include() and require() functions in a safe manner.
Eliminating the security flaws exploited by the newer versions of Santy involves no new tricks, and is simply a matter of applying long-known sound programming principles. K-OTik pointed site designers to this guide to secure programming (in French) in PHP, written in 2001.
Lien d'origine du message ci-haut:
http://www.pcworld.com/news/article/0,aid,119051,tk,dn122704X,00.asp
Message original : re SANTY A
Un nouveau ver, Santy.A., attaque les serveurs hôtes de forum phpBB comme celui-ci !!!
Les ordinateurs personnels des visiteurs du forum ne sont pas attaqués cependant.
Les fichiers présents sur le Forum sont alors effacés et remplacés par le mots suivants :
"This site is defaced!!! NeverEverNoSanity WebWorm generation,"
Rien de grave pour l'usager mais chiant pour les administrateurs du Forum.
Espérant que ce nouveau forum ne sera pas infecté alors qu'il en est encore à "percer ses dents" !!!
Voir plus de détails ici :
http://www.pcworld.com/news/article/0,aid,119024,tk,dn122204X,00.asp
Les Versions B et C du ver SANTY pouvant attaquer les serveurs de forums utilisants phpBB sont actuellement lâchés lousses ...
Plus virulents que la version A
Note - Aucun danger pour les utilisateurs du forum
Lundi 27 décembre 2004
New Variant of Santy Worm Spreads
Latest worm poses a risk to many Web sites using the PHP scripting language.
Peter Sayer, IDG News Service
Monday, December 27, 2004
The latest version of the Santy worm poses an elevated risk to many Web sites built using the PHP scripting language, security experts warn. Protecting those sites may involve individually recoding them, those security experts say.
Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software. However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warn.
Santy.C and Santy.E behave so differently from Santy.A that the K-OTik is renaming the worm PhpInclude.Worm in its advisories, the company says. The worm doesn't exploit the vulnerabilities in phpBB targeted by its predecessor, instead aiming for a wider range of common programming errors in PHP Web pages.
It uses search engines including Google, Yahoo, and AOL to identify exploitable Web pages written in PHP which use the functions "include()" and "require()" in an insecure manner, K-OTik says.
Embedded Contents
These functions can be used to embed the contents of a file within a Web page. If the site designer used them without sufficient checking of the parameters passed to the function, then an attacker could exploit them to incorporate an arbitrary file in the Web page, rather than the limited range presumably intended by the site designer. From there, depending on the configuration of the Web server, the attacker could move on to take control of the entire machine, K-OTik warns.
To prevent these attacks, it may be necessary to recode the site to use the include() and require() functions in a safe manner.
Eliminating the security flaws exploited by the newer versions of Santy involves no new tricks, and is simply a matter of applying long-known sound programming principles. K-OTik pointed site designers to this guide to secure programming (in French) in PHP, written in 2001.
Lien d'origine du message ci-haut:
http://www.pcworld.com/news/article/0,aid,119051,tk,dn122704X,00.asp
Message original : re SANTY A
Un nouveau ver, Santy.A., attaque les serveurs hôtes de forum phpBB comme celui-ci !!!
Les ordinateurs personnels des visiteurs du forum ne sont pas attaqués cependant.
Les fichiers présents sur le Forum sont alors effacés et remplacés par le mots suivants :
"This site is defaced!!! NeverEverNoSanity WebWorm generation,"
Rien de grave pour l'usager mais chiant pour les administrateurs du Forum.
Espérant que ce nouveau forum ne sera pas infecté alors qu'il en est encore à "percer ses dents" !!!
Voir plus de détails ici :
http://www.pcworld.com/news/article/0,aid,119024,tk,dn122204X,00.asp