Anti-Santy Worm Patches phpBB Flaw
sebFlyte writes "Interesting Santy worm story -- there's now an anti-Santy worm proliferating, which spreads the same way as a normal worm, but rather than killing machines or taking control of them, it gives them security updates..." We mentioned the Santy worm about ten days ago.
Is reporting that they don't know if the worm actually patches it sucessfully. For all we know, it could be infecting the System. When searching, only 3 results came up.
worms that remove/kill the MS OS is the same as a security patch?
"You see Mom, there are Good worms and there are Bad worms"
I feel that white worms, when done correctly, are a good thing. This is a case where the ends justify the means, even if it does mean comprimising vulnerable systems.
bash: rtfm: command not found
Is it possible the "benevolent" worm actually does damage covertly? Has this been investigated thoroughly?
A blog like any other.
The author of this worm still doesn't have permission to modify the source code running on people's servers. Yes, they may be idiots, but idiots still have rights (for the moment).
...and the Santy worm come in contact, would it cause the server to asplode in a brilliant flash of light?
The problem with a "good" virus, is that because of an oversight, it may cause more damage. It could open up a new expliot, or subtly damage a part of the server.
- Sites that have been attacked by the anti-Santy worm are defaced with the words: "viewtopic.php secured by Anti-Santy-Worm V4. Your site is a bit safer, but upgrade to >= 2.0.11."
If I break into your house and clean your bathroom you could call me beneficial, but you might get a little upset if I used spray-paint to write "This house is a bit cleaner, but buy some Lysol" on your front door.Using a worm as a way to help instead of wreak havoc, this is an interesting idea. Why don't they carry this idea over to Spam and use it to send me things I'm actually interested in?
How long before someone makes an "Anti-IE" worm that automaticaly installs FF on everyone's computers.
I'm not a doctor, but I play one in bed.
Even if the worm patched the site without defacing it yet again, it's still going to bog down networks by replicating. Perhaps a better alternative would be to send a simple e-mail to vulnerable sites and allow them to make the decision to patch or upgrade to the newest version.
Sure, and thanks! I appreciate it. My ip is 127.0.0.1. Let me know if you find anything worth patching!
bash: rtfm: command not found
Driftwood: "It's alright, that's in every contract! That's what they call the 'Sanity Clause.'"
Fiorello: "Ha-ha-ha-ha-ha. You can't fool me...there ain't no Sanity Clause."
Oh my God! I've never seen so much child and bestiality porn! You sicken me.
The "success" of viruses and worms so far have been characterised by their ability to reproduce. This bears some resemblance to their genetic counterparts.
Perhaps the next phase will be a virus or worm that follows genetic theory. The genetic features that would have to be modelled would be:
1) it is considered beneficial
2) it can reproduce
3) it can mutate
The successful entities would then survive, and the unsucessful mutations would die out. Survival of the fittest?
... well, to me anyway because I just don't know. There are a lot of distros out there, including all the various "live" versions, and various ways to install. I am wondering, is there such a beast as a no brainer, one click to install Linux distro that works over the internet and would seamlessly replace a users windows install with a working and safe while downloading and installing linux distro? I mean, a windows user (or another linux user, whatever) clicks on a webpage link and off she goes? With broadband now, it's common to downloand an ISO and burn it, I was just wondering if there was a distro that was designed from the ground up to eliminate that intermediary step. Say someone had finally just had it with windows problems, just said to heck with it, just replace this whole mess with something else, etc. Click, download, install, as easy as a normal app? I know there are "network" installs, but those are usually targeted at corporations where a lot of PCs are on the LAN, etc, I mean one for joe raw beginner newbie home user surfer.
Full code of asw.txt here....
This is the code of the worm extracted from a vulnerable box.
# asw: anti santy worm
# this worm will try to fix any viewtopic.php on local box
# will use this box for 1 day to search other buggy phpBB forums, and end.
etc...
If you cannot stop people from doing dumb things and running systems that are open to this sort of abuse, then at least they could be nice enough to not bother the rest of us.
/. programming. Had this been of actual importance, you would have been instructed where to browse for further news and information. This is only a rant.
I need a router/switch/filter that recognises worm/virus traffic for what it is and sets QOS down (or out) on such traffic. Better yet, I want my internet provider to have one. So the neighbor next door's got twelve sessions of Butt Trumpet running on his PC and more broadband in Mbps than he has brain cells to rub together, doesn't mean the pipes I use outta here need to be effected.
Niceties would be an ability to recognise interactive traffic and flag it for regular service. Not an original idea, by the by, was first mentioned in sf by John Brunner some years back.
Another project I will never get round to.
This is the end of the rant. We now return you to your regularly scheduled
*whup* "Get along, little electrons. Heeyah!"