Re: Worm hitting PHPbb2 Forums

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 12/21/04

  • Next message: Mike: "RE: Worm hitting PHPbb2 Forums"
    To: incidents@securityfocus.com
    Date: Tue, 21 Dec 2004 21:00:04 +0000
    
    
    

    On Tue, 2004-12-21 at 12:21 -0700, lists wrote:
    > Yea good catch, after looking into it a little further I found that it
    > wasn't related to that advisory, but rather to one from 11.13.04, the
    > exploit code of the original bug can be found on k-otik.com
    >
    > Thanks for the info

    More information:

    Mis-reported and then corrected at the ISC -
    http://isc.sans.org/diary.php?date=2004-12-21

    * The advisory is here - htp://howdark.com/
    (it was there when the advisory was initially released but that site
    seems down atm, included here in hope that howdark.com resurfaces)

    * The fix is here - http://www.phpbb.com/phpBB/viewtopic.php?t=240513

    * The exploit is here - http://www.howdark.com/poc/phpbb2010_hl.phps
    (down as above, but included here as it was the original source, try
    here http://www.k-otik.com/exploits/20041122.r57phpbb2010.pl.php )

    * SNORT Rule is here - http://www.webservertalk.com/message554529.html

    * If you got owned by this then your Christmas present is here
    http://ysati.com hehe ;-P

    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue

      http://www.bsrf.org.uk

    [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]

    
    



  • Next message: Mike: "RE: Worm hitting PHPbb2 Forums"

    Relevant Pages

    • SYMSA-2008-001: Lyris ListManager - Multiple Vulnerabilities
      ... Advisory ID: SYMSA-2008-001 ... mailing lists by modifying client side information sent to the server. ... For details on Symantec's Vulnerability Reporting Policy: ... Symantec Vulnerability Research Advisory Archive: ...
      (Bugtraq)
    • [Full-Disclosure] full disclosure lists
      ... > Vulnwatch is another full disclosure mailing list. ... It is an advisory only ... crossposted to all N mailing lists, which makes it stand out a little. ...
      (Full-Disclosure)
    • [Full-Disclosure] full disclosure lists
      ... > Vulnwatch is another full disclosure mailing list. ... It is an advisory only ... crossposted to all N mailing lists, which makes it stand out a little. ...
      (Full-Disclosure)
    • [Full-Disclosure] full disclosure lists
      ... > Vulnwatch is another full disclosure mailing list. ... It is an advisory only ... crossposted to all N mailing lists, which makes it stand out a little. ...
      (Full-Disclosure)
    • [Full-Disclosure] full disclosure lists
      ... > Vulnwatch is another full disclosure mailing list. ... It is an advisory only ... crossposted to all N mailing lists, which makes it stand out a little. ...
      (Full-Disclosure)