Cracked... Sort of

By Timothy R Butler | Posted at 5:12 AM

My server was attacked via a php vulnerability today. I had overlooked that I was still running 4.3.9, which can be broken into by the Santy worm. As it turns out, I was instead attacked by the “Anti-Santy Worm” (ASW), which doesn't seem to be wide spread enough to come up in Google yet. The ASW was only ability to obtain nobody privileges on the server, which — best as I can tell — allowed it to do nothing other than replicate. The server was not rooted, fortunately, if it had… well, I don't want to think about that. Ya know what I mean?

Again, its still somewhat speculation at the moment, as I've found my mind too muddled to read Perl fluently today, but I think it looks like a worm that actually tries to repair the vulnerabilities it finds on phpBB boards (the main mode of attack for the Santy worm) rather than doing anything destructive. Interesting, but disturbing that it was able to execute itself on the server, even with virtually no privileges — I thought I'd taken care of such things. Now I've upgraded to the latest Apache 1.x and PHP 4.x which is suppose to fix these problems (note, that like most production servers, this one does not run Apache 2.x or PHP 5.x yet).

Unfortunately, I've killed all of the WordPress blogs on the server in the process. I'm recompiling Apache again in hopes of fixing that. If not, I think I'll just jump off a cliff — that's the easiest solution.

I can't take any more this week. My mind is too muddled. Well, I shouldn't say that, but I have found that for the last day or two I've been having a hard time bringing words to mind at times. I need a few uneventful days. Just a few.

Update (2004/12/30 11:33 PM): It seems I fixed the problem. I didn't upgrade Zend Optimizer after doing the PHP update necessary to secure things. The latest PHP was incompatible with the older version of Zend I was using. Now things work again, hopefully in a much more secure fashion.


Join the Conversation

4 comments posted so far.

I’ve reading a bit about PHP 5 lately (Christmas present), but I’m still not sure if Apache 1 or 2 is the best option. Some say that the Apache2/PHP5 combination is more stable? Do you know anything about this? (Answer only if you find the subject interesting, btw, I only asked out of general interest.)

Posted by Flip - Dec 31, 2004 | 1:25 PM- Location: Sweden

Wow. Just amazing. Glad it is working.

Posted by Christopher - Jan 02, 2005 | 12:10 AM- Location: MO

That Zend Optimizer has biten a couple of times now hasn’t it? What is it supposed to do? Sounds like a hassle.

Posted by Josiah Ritchie - Jan 03, 2005 | 4:44 PM- Location: Lanham, MD

re: Zend

Zend is necessary for running copy protected PHP software. It also supposedly makes PHP run faster. It’s a necessary evil, although I think for the most part, I had resolved everything until just now.

Posted by Timothy R. Butler - Jan 05, 2005 | 1:31 AM- Location: St. Louis, MO

Create or Sign In to Your Account

Post as a Visitor

:mrgreen: :neutral: :twisted: :arrow: :shock: :smile: :???: :cool: :evil: :grin: :idea: :oops: :razz: :roll: :wink: :cry: :eek: :lol: :mad: :sad: :!: :?:
Remember my information