March 20, 2010

12/21: Santy Worm Infects Web Servers

A new worm Santy has started spreading that infects only web servers, not end user computers. It infects sites running the popular phpBB discussion forum software. Santy uses Google search to find randomly other hosts. Part of the search contains "viewtopic.php".

The worm overwrites several different files such as .php and .htm. The result is that the files are replaced with the text:

This site is defaced!!!
NeverEverNoSanity WebWorm generation X
...where X keeps growing from one infection to another.

More information can be found at this F-Secure page.

1
IT Offers

Partners