Net worm using Google to spread

A Web worm that identifies potential victims by searching Google is spreading among online bulletin boards using a vulnerable version of the program phpBB, security professionals said on Tuesday.

The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread, according to updated analyses. The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement.

Almost 40,000 sites may have already been infected. Using Microsoft's Search engine to scan for the phrase "NeverEverNoSanity" -- part of the defacement text that the Santy worm uses to replace files on infected Web sites -- returns nearly 39,000 hits.

"Santy.a is spreading rapidly," antivirus firm Kaspersky stated in a new release published on Tuesday. "However, this does not directly affect users. Although the worm infects Web sites, it does not infect computers used to view those sites."

The worm sends Google a specific search request, essentially asking for a list of vulnerable sites. Armed with the list, the worm then attempts to spread to those sites using a PHP request designed to exploit the phpBB bulletin board software.

The worm is the latest twist on using Google as an attack tool, a practice known as Google hacking.

Around 6 million sites appear to be running the phpBB software, according to a search of Google for the phrase "Powered by phpBB"--an acknowledgment appended to the bottom of any site that uses the software.

"There are tons of these PHP bulletin board installs around," said Johannes Ullrich, chief technology officer of the Internet Storm Center, which tracks online threats.

Initial analyses by the ISC had concluded that the flaw exploited by the worm occurred in the software that interprets Web pages written scripting language PHP: Hypertext Preprocessor (PHP). That flaw was found last week.

Using Google to determine vulnerable sites is not an academic exercise. The worm does exactly that: Once Santy infects a Web site, it searches Google for other sites running phpBB and then attempts to infect those sites as well.

After it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation X," according to Kaspersky. For "X," the worm inserts a number representing how far the current instance of the program is descended from the original worm release. MSN searches have found 24th generations of the worm.

Google did not immediately comment on the worm, but a spokesman did say that the company had seen the information and had started to study the issue.

The response, or lack thereof, frustrated some members of the antivirus community, who believed that the search giant could easily stop the worm by filtering out its search for victims.

"We know exactly which searches to stop," said Mikko Hypponen, research director of antivirus firm F-Secure. "It would be trivial to stop this thing."

Web sites using a vulnerable version of phpBB should upgrade, the phpBB Project site advises.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

9 minutes ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

21 minutes ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

32 minutes ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

41 minutes ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

45 minutes ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

53 minutes ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

57 minutes ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

57 minutes ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

1 hour ago by mathew42 on NBN users opt for 100Mbps

Considering that Quigley wrote the corporate plan based on a number of studies one would expect him and the plan to know best.

1 hour ago by mathew42 on NBN users opt for 100Mbps

yep don't worry, I'm sure the anti-NBN zealots will find some other ridiculous line to fill the void. I imagine it'll be "oh but these ar...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

You would think so, but after this post went live Turnbull's office finally got back to me and said that, if they win office next year, t...

1 hour ago by braue on NBN cost-benefit analyses are so 2011

Carriage dialect poke is a vastly predominant brand in a completely logical price. Honourableness quality of products of the modern coach...

1 hour ago by Teleuplique on Appeal to save wiki-linked Twitter accounts

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

You don't appear to understand what the CVC charge is. The CVC is a charge that the ISP pays and is waived while there's too few people c...

2 hours ago by OxleyDave on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Well, indeed Beta; indeed! Of course, the response to actual favourable data about the NBN is the same everywhere - out come the concern...

2 hours ago by Gwyntaglaw on NBN users opt for 100Mbps

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

But, but, but... they could do that on dial-up ;-)

2 hours ago by Beta on NBN's Tassie upgrade to cost $1.3 million

The rural Silicon Valley http://t.co/vqV6bl5i

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

Build your own smartphone stand http://t.co/IY6VxA7n

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

You don't need Mathew Gwyn, you have the other usual suspects rolling in with their FUD, like clockwork. Of course these two perpetually...

2 hours ago by Beta on NBN users opt for 100Mbps

Another way of saying that is "of the 3,500-11,000 [votes], they won't be representative of the approximately 10 million... households". ...

2 hours ago by Gwyntaglaw on NBN users opt for 100Mbps

The rural Silicon Valley http://t.co/jhEFQwSX

JobWatch: where the ICT jobs are http://t.co/e6gQvhxz via @zdnetaustralia #ICT #recruitment

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

Sweet: "Customers are picking the top fibre plan that is available on the #NBN more than any other plan" http://t.co/yUFHdYFc

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

Interesting tech analysis podcast re: phone cloning and Craig Thomson from zdnet http://t.co/p8jlCvvG

@zdnetaustralia Thoughtful piece to end the week on. Thanks @joshgnosis

Triple J's Spotify conundrum http://t.co/iy1e2DRp via @zdnetaustralia

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

BYOD for iOS devices is not a big deal, provided a passcode is enforced and jailbroken devices are excluded. But if Google can sort out ...

3 hours ago by umbria on BYOD too immature for us: Human Services

Triple J not bound to advertising rules like its broadcast. No diff to ABC online or magazines though... http://t.co/JPUr7Fv4

Triple J's Spotify conundrum: Has Triple J managed to find the balance between meeting editorial policy and keep... http://t.co/8UYsHZ6D

Thank you, Tasmania, for helping NBNCo get the design optimised. Heard a great anecdote this week. Four kids at a little school in one of...

3 hours ago by umbria on NBN's Tassie upgrade to cost $1.3 million

RT @joshgnosis: Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

How does Triple J find the balance with meeting editorial policy and keeping up with the latest technology? http://t.co/qdWgybfm ^jt

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

NBN users opt for 100Mbps http://t.co/ftKGRzye

#IT Priorities: #servers and #storage: webinar sponsored by @IBM http://t.co/BGq8LYd5 via @zdnetaustralia

Post 'social' improved speed to information and context: By Oliver Marks | May 24, 2012, 9:47pm PDT... http://t.co/VGN2hxtp #socialmedia

RT @zdnetaustralia: Should bug hunting for biometric systems be restricted to govt and industry? http://t.co/oj0oOkv7 ^ML

Exploring: http://t.co/WzikDISk

IT Priorities: servers and storage http://t.co/BGq8LYd5 via @zdnetaustralia

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar