Anti-Santy Worm Patches phpBB Flaw
sebFlyte writes "Interesting Santy worm story -- there's now an anti-Santy worm proliferating, which spreads the same way as a normal worm, but rather than killing machines or taking control of them, it gives them security updates..." We mentioned the Santy worm about ten days ago.
Is it possible the "benevolent" worm actually does damage covertly? Has this been investigated thoroughly?
A blog like any other.
The author of this worm still doesn't have permission to modify the source code running on people's servers. Yes, they may be idiots, but idiots still have rights (for the moment).
The problem with a "good" virus, is that because of an oversight, it may cause more damage. It could open up a new expliot, or subtly damage a part of the server.
Till the worm installs a security patch that causes a bug that it takes someone hours upon hours of debugging to locate. People should be allowed to patch when they want. Patches aren't always 100% correct, and some can cause some major havoc. Let each person decide if/when the patch is needed...
Monstar L
- Sites that have been attacked by the anti-Santy worm are defaced with the words: "viewtopic.php secured by Anti-Santy-Worm V4. Your site is a bit safer, but upgrade to >= 2.0.11."
If I break into your house and clean your bathroom you could call me beneficial, but you might get a little upset if I used spray-paint to write "This house is a bit cleaner, but buy some Lysol" on your front door.In principle they seem good, but what about when a white worm installs a patch that interferes with legitimate operation of the system? It is perfectly possible a vulnerability was left alone by the operator because the patch would have rendered the system unusable and that security measures external to the vulnerable system render the vulnerability moot.
Of course, such machines aren't the ones likely to intersect common worm spread vectors...
Trouble making decisions? Just flip for it.
The ends justify the means? I don't think so! When the white worm author determines what the ends are, and what correctly is, it is still just a worm. Anything installed behind my back on my computer is bad, evil, no-good-nick!
*click**beep**beep* Scotty, One to Mod up!
### Patches aren't always 100% correct, and some can cause some major havoc.
If I have the choice between havoc caused by a patch and havoc caused by a hostile breakin into the system, I'll pick the havoc caused by the patch, that at least doesn't leave any hidden backdoors behind.
This sounds really great in theory. Unfortunately, I know too many people who politely explained to someone that that had a security problem, just to have an embarressed admin turn around and claim that the person pointing it out must a hacker breaking into the system.
I even know a case where a person explained that the password on windows 95 was not meant for security purposes and that you could bypass it by clicking cancel, just to be reprimanded for breaking into computers he was authorized to use.
These day's, I would think real hard before telling somebody you don't know that they have a security problem. People don't turn down the opporunity to punish good deeds often enough.
BTW. I'm not saying the worm is a good idea. Even if the intentions are all good, if it fails in some unexpected way, it is still the author's fault. He/she has no right to be tampering with other people's system without their permission.
No matter the intent, the worm doesn't take into account all the variables that go into a box. Maybe 95% of the users who get it ARE idiots, as a lot of posters have said, but the 5% left may have their reasons...
Aside from this fact, and the fact that there is no QA and little testing before hitting the mainstream, it causes a lot of excess, innefficient i-net traffic, which for a long time was the primary annoyance of mass-stream virii.
If it comes into your system, your system was insecure. By running an insecure system, you harm us all by helping worms & viruses to spread.
I think worms that go around closing the security holes that let them in are a Good Thing and it's about time they started appearing.
I disagree.
I very nearly wrote an anti-code-blue worm a few years back, and got to the point of payload (patch) deployment when the glaring flaw came to me: any time that you or a program that you made does something unexpected, or makes a connection to another machine, YOU are liable for what happens. Given that heterogeneous computers and networks exist, can you test for 100% of all possible cases? Likely not.
It's not so much that I disagree with the sentiment, you see, but I find it impossible to ever run into the case that a white worm is done correctly and can be certified as such.In the example above, for instance, all that an attacker would have to do would be to infect a netblock with Code Blue, point them at my anti-blue worm launcher, and then watch the fun as I "cause" a DDOS with all the network traffic that will go spewing back and forth between the two sites. The attacker has now been able to effect the Availability of two sites in one go. Not exactly something that I'd like my name attached to, hence the reason that no anti-code-blue-worms have been released into the wild from me.
What I see is a company saying we are first to report but we wont say anything that can be good for our "enemy". There is nothing difficult about testing its efficiency but it is not in their interest.
I am not saying this worm is good, but that if they wanted to verify it would be easy.
But if they are in charge and haven't patched against a malicious worm, they have no cause to complain when a white worm gets in first and possibly causes problems from patching the exploit, rather than definately causing harm when the black worm comes by.
"I was just taking reasonable steps to protect my property from the attacks of others"
What kind of sewed vision of the world do you have that would allow you to make such a comment?
If a person is intelligent enough to patch their system, then they need not worry about the worm, as they will have patched their systems against it! Those not intelligent enough to patch their systems will get infected, and then have their system patched, its win-win.
It is a similar concept to those bar code scanners we have at work: The letters of the alphabet are arranged in alphabetical order (used to input username and password), ostensibly so that those who are not familiar with QWERTY keyboards can find the letters easier, which is the stupidest idea I have ever heard of, and seen implemented, because _EVERYONE_ now has to hunt and peck on those dammed things, even those who are familiar with QWERTY keyboards. I know the alphabet, but try to find a single letter on those scanners is maddening.
If everyone were using the same indentical machines and configuration, then perhaps. But that's just not going to be the case.
Here's my take on these types of worms:
I have evidence which leads me to strongly believe that your kitchen faucet is leaking, badly. This will no doubt cause flooding and damage. Instead of warning you about it, I (a random citizen) will now fix this problem for you.
Of course, since I don't know your home, I may break something unrelated to your current problem. But don't worry, because I'll be back to fix THAT problem later, in the same fashion (at which time I might break something else, etc etc).
This is not my sig.