[Mediawiki-l] Possible Worm Target on 1.3.9?

Pádraic Brady maugrimtr at hotmail.com
Thu Dec 23 10:30:12 UTC 2004


I have a small problem.

Recently a worm has been assailing the web (using Google to search out new 
victims). I had MediaWiki installed alongside phpBB on PHP 4.3.9. After PHP 
released 4.1.10 (which was duly installed by my host) the worm began making 
the rounds. phpBB was the primary target - luckily phpBB released a patched 
version to block any potential attack by the worm.

Unfortunately even with PHP 4.1.10, and the new phpBB - MediaWiki is being 
hit hard. It's the only PHP application effected on my server. Here's the 
worm's message which it leaves behind:

This site is defaced!!!
NeverEverNoSanity WebWorm generation 25.
[pear_error: message="Template function 
'tpl_0_7_0_d709070e8418c9bc7d313434ecea7226' not found (template source : 
/home/groups/e/es/esun/htdocs/wiki/templates/xhtml_slim.pt" code=0 
mode=return level=notice prefix="" info=""]

I still need to track which files were effected or how the worm works - but 
thought I'd post it here. You all do great work - :) and I'm cool with 
waiting for whatever issue (whether my host or the wiki app) to resolve 
itself in time.

-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-
Pádraic Brady

aka Maugrim The Reaper
http://www.quantum-star.com/
http://www.shadowsrising.net/
-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-|-





More information about the MediaWiki-l mailing list