Alarm Security: arrives PhpInclude.Worm



January 2, 2005 by tammax
Section: The web

The new bug PhpInclude.Worm spreads on the Internet today, you
attached to each dynamic page is not secure. (This bug is currently
classified by the virus as an alternative to Santy. Not acting in
Santy same way, it was decided to separate this bug family Santy:
name "PhpInclude.Worm" is therefore susceptible to change. Unlike
Santy, PhpInclude.Worm phpBB does not exploit the vulnerabilities, exploits a
wider range of defects called "programming". Search (via / Yahoo / AOL)
Web servers whose pages use php functions include () and
require () on a non-secure. These functions are normally used
programmers to include web pages in arguments. Unfortunately, no
verification of these arguments may allow the inclusion and implementation of
external archives, and thus compromise the web server. PhpInclude.Worm
So search the pages of type * php? * =, Then
attempt to enter multiple commands that allow the installation of robots and IRC
the establishment of an army of zombies machines. These faults current
are related to web applications and not the platform or version of
PHP, where a qualified high risk by K-Otik Security.

Related articles:


Leave a comment

;):|:x:twisted::)8O:(:roll::P:oops::o:mrgreen::lol::idea::D:evil::cry:8):arrow::?:?::!:

Immagine CAPTCHA Audio version
Reload image