Welcome Guest ( Log In | Register )

  Recent Software News
Phel Trojan targets Windows flaw
Cabir cell phone threat worsens
19 LingvoSoft dictionaries for Wind...
Microsoft posts critical configurat...
Apple ships Mac OS X update
  Recent Gaming News
Electronic Arts to buy into Ubi Sof...
Halo 2, San Andreas key drivers of ...
Sony Says All Systems Go for PSP La...
Nvidia to work on PlayStation 3 chi...
New Command & Conquer Game Unveiled
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
How to enable use of nvidia dr...
Windows XP Sp2 Problems
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Santy Worm Moves On






   
Santy Worm Moves On
Posted by mitchy_g on 31 Dec 2004 - 06:18 0 comments
Previous Post | Tech News | Next Post
 
Less than a week after Google (Quote, Chart) squashed the Santy.A worm, variants of the virus are reportedly spreading through other online search engines, including America Online (Quote, Chart) and Yahoo (Quote, Chart), according to several security firms.

While the early version moved rapidly by exploiting flaws in the popular phpBB discussion forum software, the latest variant is germinating through the wild by attacking Web sites using the PHP scripting language, according to Ken Dunham, director of malicious code at Virginia-based security firm iDefense.

"There are several different threat scenarios," he said, adding that several variants, including Santy.B through Santy.E, have evolved since last week.

Dunham said the virus did not appear to be too widespread and expected the outbreak to remain relatively controlled.

However, several security firms have reported Web sites being infected and servers being compromised or slowed due to the virus.

Santy.A was discovered by Helsinki, Finland-based F-secure last Tuesday, menacing tens of thousands of Web sites that used the popular program to create Internet forums. It raced through the wild, and in a few hours disabled and defaced nearly 40,000 sites leaving the message: "This site is defaced!!! NeverEverNoSanity."

As reported earlier on internetnews.com, the worm spread on its own and did not require user interaction. Instead, it searched for vulnerable forum sites through Google and used a remote exploit to gain access to them. Once it located a site, it defaced it and restarted the random scanning process for more hosts.

But Santy.A was halted after Google began blocking infected sites, slowing down the spread of the virus. Now the virus is using Yahoo and AOL search engines to avoid being blocked by Google.

AOL, which uses Google's search engine technology, is still investigating the possibility that it may need to take additional steps to prevent the virus from infecting Web sites through its search, according to Andrew Weinstein, a company spokesman.

It was unclear whether the initial response by Google was sufficient to protect AOL searches from the virus.

In a statement to internetnews.com, a Yahoo spokesman said: "We became aware of the Santy.B worm on December 24 and immediately took action to protect websites and our users. The worm has caused very little impact."

The recent spike of viruses spreading through search engines, including the MyDoom worm early this year, is a trend likely to continue as more and more search engines find themselves in the crosshairs of virus writers, said Dunham of iDefense.

"Search engines should plan on having programs abused in 2005," he said.

Although Google was initially criticized for a sluggish response to the Santy threat, Dunham says the company acted in time to stop the continued spread of the worm.

News source: InternetNews

There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)