Quantcast

New Variant of Santy Worm Spreads

Latest worm poses a risk to many Web sites using the PHP scripting language.

Peter Sayer, IDG News Service

  • 0 Yes
  • 0 No

The latest version of the Santy worm poses an elevated risk to many Web sites built using the PHP scripting language, security experts warn. Protecting those sites may involve individually recoding them, those security experts say.

Early versions of the Santy worm exploited a specific bug in a bulletin-board software package called phpBB, and their attacks could be prevented by applying a patch to the software. However, the security flaw exploited by newer versions of the worm such as Santy.C or Santy.E is more general, and can occur anywhere a site designer has left the door open for the inclusion of arbitrary files into PHP scripts, experts at K-OTik Security in Montpellier, France, warn.

Santy.C and Santy.E behave so differently from Santy.A that the K-OTik is renaming the worm PhpInclude.Worm in its advisories, the company says. The worm doesn't exploit the vulnerabilities in phpBB targeted by its predecessor, instead aiming for a wider range of common programming errors in PHP Web pages.

It uses search engines including Google, Yahoo, and AOL to identify exploitable Web pages written in PHP which use the functions "include()" and "require()" in an insecure manner, K-OTik says.

Embedded Contents

These functions can be used to embed the contents of a file within a Web page. If the site designer used them without sufficient checking of the parameters passed to the function, then an attacker could exploit them to incorporate an arbitrary file in the Web page, rather than the limited range presumably intended by the site designer. From there, depending on the configuration of the Web server, the attacker could move on to take control of the entire machine, K-OTik warns.

To prevent these attacks, it may be necessary to recode the site to use the include() and require() functions in a safe manner.

Eliminating the security flaws exploited by the newer versions of Santy involves no new tricks, and is simply a matter of applying long-known sound programming principles. K-OTik pointed site designers to this guide to secure programming (in French) in PHP, written in 2001.

  • Recommend this story?
  • 0 Yes
    0 No

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Related Security Articles

  • Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
  • PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
  • A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)