Darkness
Hand and Eye of Piratecat [Moderator]
randomling said:The bad news: I still have no idea what really happened, though it looks like somebody just went into my web-hosting account and changed the HTML of all the index pages.
I found this on rpg.net:
From: "Jonathan Glass" - Find messages by this author
Date: Tue, 21 Dec 2004 1411 -0500
Local: Tues, Dec 21 2004 11:13 am
Subject: RE: [Ring-of-Fire] Possible apache2/php 4.3.9 worm
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Risk:
A new PHP worm is spreading, defacing web sites running
phpPBB. This worm overwrites all .php and .asp and .html files which
are writable to the user under which Apache is running, and replaces
their contents with "This site is defaced!!!" NeverEverNoSanity in
bold red.
Mitigation:
If you are running phpBB, please download the latest version
(2.0.11) or follow the workaround on the following site:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046
The 2.0.11 Version has been available since November 18, 2004. Here
is the release:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240636
Technical Information:
For more information on the worm, please see the following.
http://www.f-secure.com/weblog/
(quoted from f-secure.com)