Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Hacking problem on our website...neverevernosanity webworm generation 13
http:// www.paxbaculum.com | 12/20/04 | armedanddangerous

Posted on 12/20/2004 7:03:43 PM PST by Armedanddangerous

Some friends and I have operated a self defense survival and conservatism website called www.paxbaculum.com .

This afternoon someone apparently took control of it with a worm called neverevernosanity webworm generation 13.


TOPICS: Miscellaneous; Technical; Your Opinion/Questions
KEYWORDS: cyberterrorism; hackers
Navigation: use the links below to view more comments.
first previous 1-2021-4041-59 last
To: Prime Choice

Thanks Prime Choice!

My level of experience is nil.

......I'm a Mac user......

Basically, I'm a stay at home mom that anticipates moving into the workforce now that my son is 8.

I'd like to work during his school hours and anticipate that PC's will be involved in my new workplace, wherever that may be.

For my two cents, I love FR because I can learn about subjects that are foreign to me, and at least learn a little bit about the language supporting them. It helps me in forming semi-intelligent questions. LOL

I love that you said that the only dumb question is the one that isn't asked. That is a treasure.!

Believe me, when I get that said job, I'll have plenty of questions.

FWIW, I've been a producer/writer for most of my career, I've been out of it for most of the past 6 years and am looking for a field that interests me and accepts a 44 year old with a broadcast journalism degree.

Please no slings and arrows! (<:

I'm no Mary Mapes. Just a cable sort.



41 posted on 12/20/2004 8:53:27 PM PST by mplsconservative (All I want for Christmas is a new pair of pajamas. My old ones are FReeped out!)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Prime Choice
Good stuff.. I liky! Nice layout, easy UI and great content. Added to my list.
42 posted on 12/20/2004 8:55:34 PM PST by Splatter (A foolish man is able to learn, has the opportunity, and does not do it..)
[ Post Reply | Private Reply | To 37 | View Replies]

To: RebelTex

Sorry RebelTex.

I forgot my FR manners, not a good thing to do.

Thanks for the reminder to include the zotee's name in the reply line. Sorry again for the confusion.

Merry Christmas to you and yours.


43 posted on 12/20/2004 8:59:03 PM PST by mplsconservative (All I want for Christmas is a new pair of pajamas. My old ones are FReeped out!)
[ Post Reply | Private Reply | To 40 | View Replies]

To: mplsconservative

Merry Christmas to you and yours, too!

I hope ya'll have the best one, ever.

Don't worry about not indicating who you wanted to zot. I was going crazy until I figured it out, then it was pretty funny. Boy, was I red-faced. No harm done, though, so don't feel bad. I should have picked up on it a lot quicker, but I guess I'm just getting old. heheh

The only reason I mentioned it was so I wouldn't feel quite so foolish.
;^D


44 posted on 12/20/2004 9:09:18 PM PST by RebelTex (Freedom is Everyone's Right... ...and Everyone's Responsibility!)
[ Post Reply | Private Reply | To 43 | View Replies]

To: RebelTex; mplsconservative
Could ya'll do me a favor and mention the poster's screen name when you start talking about zotting someone. It sure would help to make more sense of the thread. I'd really appreciate it.

Sure thing. The joker was named 'johnny3' and he was repeatedly linking to some powerpoint presentation at "summeroftruth.org." Turns out the site is a whacked-out Leftist k0n5p1r4cy k00k site that insisted that the Republican party was behind the 9/11 attacks. Truly screwed-up stuff.

The idiot in question was something of a sleeper troll who had signed up in October and chose tonight to go turbo-jackwit.

45 posted on 12/20/2004 9:13:45 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: RebelTex

Oh you sweetie, you!

No harm done.

Things can get "convoluted" (hope I spelled that right) when I'm replying on a few threads at once.

I'm heading for the roundhouse now.

Waaay too much Christmas shopping to be accomplished tomorrow! (:

Hope y'all have a wonderful Christmas, FReepers one and all!


46 posted on 12/20/2004 9:20:07 PM PST by mplsconservative (All I want for Christmas is a new pair of pajamas. My old ones are FReeped out!)
[ Post Reply | Private Reply | To 44 | View Replies]

To: Prime Choice

"The idiot in question was something of a sleeper troll who had signed up in October and chose tonight to go turbo-jackwit."

Turbo-jack wit."

Now that's a phrase I can live with and appreciate

I've got a Jack Russell Terrier, named Sparky, who turns a year old on Dec. 29th.

He assumes the Turbo Jack Wit stance several times daily.

Good talking with you Prime Choice.


47 posted on 12/20/2004 9:28:40 PM PST by mplsconservative (All I want for Christmas is a new pair of pajamas. My old ones are FReeped out!)
[ Post Reply | Private Reply | To 45 | View Replies]

To: Prime Choice

Thanks for clearing that up, Prime Choice.

Now, I understand why he was zotted. It seems like the trolls are always zotted before I can read their posts.

Dang - I'd sure like to zot one, heheh. (Maybe I'll catch one for Christmas.)
:^D

Ya'll have a Merry Christmas, now, ya hear.


48 posted on 12/20/2004 9:30:12 PM PST by RebelTex (Freedom is Everyone's Right... ...and Everyone's Responsibility!)
[ Post Reply | Private Reply | To 45 | View Replies]

To: mplsconservative
Yeah, I'm just reading them. They sound like their from another planet speaking some weird language...cool huh.

If I can do on/off, and hit print....my day is made.

49 posted on 12/20/2004 9:50:47 PM PST by processing please hold (Islam and Christianity do not mix ----9-11 taught us that)
[ Post Reply | Private Reply | To 30 | View Replies]

To: mplsconservative
I've got a Jack Russell Terrier, named Sparky, who turns a year old on Dec. 29th. He assumes the Turbo Jack Wit stance several times daily.

Heh. Well, rest assured that any dog at its worst is far more behaved and polite than any rabid Leftist at their best. ;o)

50 posted on 12/20/2004 11:18:15 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 47 | View Replies]

To: RebelTex
It seems like the trolls are always zotted before I can read their posts.

Dang - I'd sure like to zot one, heheh. (Maybe I'll catch one for Christmas.)

I got a target practice troll here. I keep him in a cardboard box (airholes optional) for just such an occasion, lemme take him out for ya.

WHOA! Flame troll! Look out!!

Sorry, Tex...he went rabid. Had to put him down.

51 posted on 12/20/2004 11:20:56 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Armedanddangerous
From: Google Groups

It is indeed a webworm, targetting the most recent vulnerabilities announced this past Friday in PHP. While I do automatic nightly updates of certain key components of my systems, this update was not yet released from my publisher. I misread their announcement, and so it is entirely my fault. If I had noticed they didn't intend to patch within 24 hours, I'd have hand-patched.

The primary purpose of this worm is to set up some sort of spam-gizmo. I have not yet completed analysis of the code, but it is Brazilian in origin and at initial glance seems to be trying to test email addresses for validity, keeping a list of good and bad email addresses. It then reported them back through IRC to someone who I assume is collecting the data in their master database to spam away using other (or possibly the same) drones. Though it would seem the folks who run Windows on their desktops are the most prone to the spam-sleepers. I guess that will teach them to trust Ol' Bill. ;)

52 posted on 12/21/2004 12:40:41 AM PST by kingu (Which would you bet on? Iraq and Afghanistan? Or Haiti and Kosovo?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Prime Choice

53 posted on 12/21/2004 12:42:48 AM PST by trussell (I Never Frown, even when I am sad,because I never know who is falling in love with my Smile!!!)
[ Post Reply | Private Reply | To 51 | View Replies]

To: Prime Choice
"Sorry, Tex...he went rabid. Had to put him down."

Now that was funny. Good thing I had already finished my coffee this morning or it would have been all over the screen.

Thanks for the wake-up laugh. Love to start my day LMAO with tears in my eyes (WTIME). It makes the whole day a little bit brighter and nicer.

;^D

54 posted on 12/21/2004 7:40:40 AM PST by RebelTex (Freedom is Everyone's Right... ...and Everyone's Responsibility!)
[ Post Reply | Private Reply | To 51 | View Replies]

To: Armedanddangerous

Information is flying across the lists about the worm that hit your site. It appears to be a worm that exploits a vulnerability in phpBB that was identified a month ago:


This bug only exploits a hole in phpBB2 as far as I can tell. It does not
appear to exploit a hole within PHP. In order to protect yourself, you
must upgrade phpBB2 to version 2.0.11.
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

See also:
http://isc.sans.org/

Generation 9 appears to overwrite files with the following extensions:
.htm, .php, .asp, .shtm, .jsp, .phtm

It only displays a defacement message saying

"NeverEverNoSanity WebWorm generation #"

Where # is the generation of the worm.


55 posted on 12/21/2004 12:44:09 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Prime Choice

http://www.glen-l.com/

Keep following the "Boatbuilder Connection" link. It went down yesterday morning.


56 posted on 12/22/2004 2:30:43 AM PST by DavidMcA
[ Post Reply | Private Reply | To 9 | View Replies]

To: DavidMcA

As a complete non-techie I would be grateful for some comments regarding this webworm. A site several of us have being using as a disussion forum got hit by generation 16 of the worm.
The site has been effectively abandoned by its owner, so they will obviously not be looking to get rid of the worm. In this situation is the site finished?


57 posted on 12/22/2004 7:55:31 AM PST by dimples1
[ Post Reply | Private Reply | To 56 | View Replies]

To: Armedanddangerous; dimples1
Here's an article about the "Santy" worm: Net worm using Google to spread


58 posted on 12/22/2004 8:34:50 AM PST by KS Flyover
[ Post Reply | Private Reply | To 1 | View Replies]

To: Armedanddangerous; Prime Choice
If you need additional info about Santy Worm you should check here http://www.kb.cert.org/vuls/id/497400 . If you have a trace on the source (other than Google), I'm sure they would like to talk to you. By now its under control but you never know. I recognized the 'neverevernosanity' tag and thought, "Hey, we were talking about that one".
59 posted on 12/25/2004 5:43:18 PM PST by Splatter (A foolish man is able to learn, has the opportunity, and does not do it..)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-59 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson