473,804 Members | 3,750 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Yet another PHP worm

3 1998
On 7 Nov 2005 17:03:26 -0800, "Chung Leong" <ch***********@ hotmail.com> wrote:
See http://www.theregister.co.uk/2005/11/07/linux_worm/


In XML_RPC, again. And the same issue, it's using eval() and getting it wrong.

Looks like they did the right thing this time, and eliminated use of eval().
--
Andy Hassall :: an**@andyh.co.u k :: http://www.andyh.co.uk
http://www.andyhsoftware.co.uk/space :: disk and FTP usage analysis tool
Nov 8 '05 #2
I don't believe the worm is using a new vulnerability. There're
probably plenty of servers with out-of-date version of that component
to exploit. A serious issue with component-programming in PHP: The
chief reason to use existing components instead of writing your own
code is to save time. It's unrealistic to expect programmers to invest
the necessary time to monitor the various components for security
updates.

Nov 8 '05 #3
JDS
On Tue, 08 Nov 2005 01:47:29 +0000, Andy Hassall wrote:
In XML_RPC, again. And the same issue, it's using eval() and getting it wrong.


Will updating the PHP XML-RPC components also fix the affected
applications? Meaning, for example, do I have to update Nucleus, or can I
just update the XML-RPC components of PHP?
Thanks

--
JDS | je*****@example .invalid
| http://www.newtnotes.com
DJMBS | http://newtnotes.com/doctor-jeff-master-brainsurgeon/

Nov 8 '05 #4

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

9
1907
by: Dennis Gearon | last post by:
<OT about the worm> Jeessh, a lot of people have my email address. I have received about 500 copies of the worm in the last 24 hours. My mail spool at work was sooooo full I couldn't get out or relay or anything. The wierd part is that it's my work address, and I'm subscribed to almost all my lists through the address above or my previous home address. YEARS ago I was using the work address for lists, but not for a LOOOOOOOOOOOONG time....
0
1319
by: RollForward Wizard | last post by:
Exciting Oracle News Oracle DB Worm Code Published http://www.eweek.com/article2/0,1895,1880682,00.asp?kc=ewnws110205dtx1k0000599 Researcher: Oracle Passwords Crack in Mere Minutes http://www.eweek.com/article2/0,1895,1878883,00.asp
14
1703
by: Chuck Grimsby | last post by:
As many of you know, I occasionally get messages from the MS team on various things. Today I got the following, and (personally) I think it certainly is worthy of passing on. If you haven't protected yourself from the sasser worm, GET THE HECK OFF THE NET!! <Grin> No, seriously, get the patch. And a firewall. Even one of the free personal ones like Zome Alarm or Outpost or whatever, and then hopefully, someday, all this ......
44
4963
by: Julian V. Noble | last post by:
Dear C Mavens, Anyone here getting hosts of spam with nefarious attachments, purporting to be from M$ or its lackeys, into your mailbox? I neglected to spoof my header, and since Hurricane Isabel I have gotten well over 10K such messages. --
1
1439
by: David H. Lipman | last post by:
w32/sdbot.worm do not download or open
0
1346
by: Mohamoss | last post by:
Microsoft has been made aware of a worm identified as “W32.Sasser.worm” and it is currently circulating on the Internet. The worm exploits the Local Security Authority Subsystem Service (LSASS) vulnerability fixed in Microsoft Security Update MS04-011 on April 13, 2004. Microsoft encourages customers to protect themselves against this worm by installing Microsoft Security Bulletin MS04-011...
0
9706
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
9584
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
0
10583
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
0
10337
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth. The Art of Business Website Design Your website is...
0
9160
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
0
5525
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
1
4301
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
2
3822
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.
3
2995
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating effective websites that not only look great but also perform exceptionally well. In this comprehensive...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.