•
•
•
•
What is DaniWeb IT Discussion Community?
You're currently browsing the PHP section within the Web Development category of DaniWeb, a massive community of 423,521 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 4,361 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our PHP advertiser: Lunarpages PHP Web Hosting
Views: 1510 | Replies: 1
![]() |
On behalf of the Security Community I have been asked to spread the word on this threat as it is very real and growing worse as time passes.
Posted on Saturday, 25 December 2004 @ 16:33:38 EST by Paul Laudanski at http://castlecops.com/
The new strain is now called Santy.c
Merry Christmas and be prepared.
Posted on Saturday, 25 December 2004 @ 16:33:38 EST by Paul Laudanski at http://castlecops.com/
•
•
•
•
Folks, it seems that Santy worm has taken on a new strain. It also searches Yahoo now in addition to Google, but it looks for any PHP scripts with all possible arguments passed thru in the HTTP GET. This worm tries all arguments in your PHP script to throw in a shell commands that access a particular website, download some text files into /tmp, and then execute them using Perl. If you are using Mod_Security, you might want to try something like this (its working for us so far):
SecFilter "visualcoders\.net/spy\.gif\?\&cmd"
SecFilter ":/"
Just in case the URL changes, the latter should still get all sorts of:
http://
ftp://
Naturally, the latter also filters on
%3a%2f
It is Christmas after all, so a quick patch to throw HTTP 406s at the requester works thru the above..
The new strain is now called Santy.c
Merry Christmas and be prepared.
•
•
Join Date: Dec 2004
Location: Fort Bragg, NC
Posts: 189
Reputation:
Rep Power: 4
Solved Threads: 3
Oo OO OO, I appriciate that. I have to go update the pages now. My site that is. Not here. I wish.
dynastyCODERS#1 when it comes to Programming Tutorials, Database designs and discussions, Operating Systems, you name it, check us out and drop us a line to tell us your opinions on any and everything in mind!;)
![]() |
•
•
•
•
•
•
•
•
DaniWeb PHP Marketplace
•
•
•
•
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
- Help my virus problems with logs and evidence (Viruses, Spyware and other Nasties)
- this compagny change my background (Viruses, Spyware and other Nasties)
- php mysql help (PHP)
- Please school me in PHP script installation. (MySQL)
- Php-nuke and MySQL trouble (PHP)
- I had a experience of a website coded in PHP (PHP)
Other Threads in the PHP Forum
- Previous Thread: No Temporary Files
- Next Thread: how to make member expire after so many days with php script


Linear Mode