phpBB worm

Locked
User avatar
derobert
Phantom of the .Org
Joined: Wed Oct 24, 2001 8:35 am
Location: Sterling, Virginia
Contact:
Org Profile

Post by derobert » Sun Dec 26, 2004 3:21 am

The current work going around, AFAIK, exploits a phpBB bug in handling of the highlight parameter to viewtopic.php. We're patched against that one (more details on that fun later).

There are also php exploits with e.g. unserialize. I don't think SuSE has released that patch yet, unfortunately....
Key 55EA59FE; fingerprint = E501 CEE3 E030 2D48 D449 274C FB3F 88C2 55EA 59FE
A mighty order of ages is born anew.              http://twitter.com/derobert

Locked

Return to “Site Help & Feedback”