New version of the Santy.A NeverEverNoSanity worm?
Someone posted on the phpBB forums, reporting that he’d had his forum defaced by a new version of the Santy.A worm.
The text this time is:
This site is defaced
::–:: NeverEverNoSanity WebWorm 2 generation 2.3 ::–::
- This time its worse, Don’t fucking try making google block us -
- The bestDeception hackers are here, and here to stay -
Until someone knowledgeable gets a sample of the code, we of course don’t know if this is a real virus that will spread.
When searching Google, I find lots of weirdness here. The site has many different flavors of forums on it, and this particular link held useBB in Google’s cache. So if it now had phpBB, it was a new installation quite recently.
I found something else on this particular site that I found funny. It’s actually a 404 page, but the 404 isn’t visible on the page. You’ll only realize it’s a 404 page if you access with the right tool. Any regular visitor with a regular browser might think the site was hacked? Weirdest 404 page I’ve ever seen. See this sample.
EDIT: They’ve found other worms, exploiting the same hole. Both in phpBB and other software:
http://www.eweek.com/article2/0,1759,1745693,00.asp
December 24th, 2004 at 3:21 am
Erm, the 404 is fucked man.. http://nsoft-rpg.com/44875 looks even worse now..
December 25th, 2004 at 3:39 pm
ROTFL!
January 12th, 2005 at 10:36 pm
“and this particular link held useBB in Google’s cache”
You mean… as in UseBB, the forum software (www.usebb.net)? If so, please drop me an e-mail.