Free Republic
Browse · Search
News/Activism
Topics · Post Article

This afternoon someone apparently took control of it with a worm called neverevernosanity webworm generation 13. Is anyone familiar with this webworm, where it came from, how the hacker might have used it or how we can get it off there?

Any way to trace it back to the person who sent the webworm? We are fairly certain we know who did it. It's just proving it..

1 posted on 12/20/2004 7:03:43 PM PST by Armedanddangerous
[ Post Reply | Private Reply | View Replies ]


To: Armedanddangerous

not too much of a problem. What is the IP address that was connecting?


2 posted on 12/20/2004 7:04:55 PM PST by shellshocked
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
First things first. Please answer these questions:

  1. What is the OS of your site?
  2. What services run on the system?
  3. Do you use FrontPage, PHP or similar services on your web server?
  4. How do you know your system was taken over by a worm (rather than an anklebiting scriptkiddy)?
  5. What is the OS of your workstations that you use to access your server?
  6. Do you have minimal safety measures on your workstation (personal firewall, current anti-virus programs, anti-spyware programs)?

Once we get some answers, we can start narrowing down the vector of the attack against your site.

5 posted on 12/20/2004 7:22:47 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

That worm hit other websites, too.

I was trying to access one business website and it showed that it had been attacked. The owners took the site down and they still haven't got it back up and running.


6 posted on 12/20/2004 7:22:57 PM PST by TomGuy (America: Best friend or worst enemy. Choose wisely.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

Run command netstat -an ?


7 posted on 12/20/2004 7:26:15 PM PST by RedBloodedAmerican
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
If you have your own server, get Zone Alarm Fire Wall (with Visual Zone for non-Pro version), Linksys NAT router, Kaspersky Anti Virus, and an IDS (packet tracker).
11 posted on 12/20/2004 7:38:41 PM PST by Wiz
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

Reported here? http://www.us-cert.gov/current/current_activity.html


12 posted on 12/20/2004 7:40:33 PM PST by Splatter (A foolish man is able to learn, has the opportunity, and does not do it..)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
For anti Spyware, get SpyBot or AdAware. Those are the best known and reliable products.
13 posted on 12/20/2004 7:42:00 PM PST by Wiz
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

Here is a new one (2 me).. http://www.securityfocus.com/bid/11981


15 posted on 12/20/2004 7:45:09 PM PST by Splatter (A foolish man is able to learn, has the opportunity, and does not do it..)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

Looks like you're running RedHat Linux (Fedora) with Apache/2.0.50. Might want to reinstall the OS from scratch, apply all the latest patches, and check to make sure all of your apps are up to date before going back online.


18 posted on 12/20/2004 7:51:27 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
This piece of freeware might help:

Sam Spade

Sam Spade for Windows is a freeware network query tool.  It may help you in tracking the perp.  It's also helpful to track & nail spammers.

Checked Symantec and McAfee and the worm you mentioned is not yet listed there.  Try checking them in a few weeks.  They are usually pretty good at catching new stuff before it really spreads too far.

Good Luck.

28 posted on 12/20/2004 8:06:14 PM PST by RebelTex (Freedom is Everyone's Right... ...and Everyone's Responsibility!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
If you go to your hacked second page you will see something like this.

DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> > HEADBODY bgcolor="#000000" text="#FF0000"> H1>This site is defaced!!! ADDRESS>NeverEverNoSanity WebWorm generation 13.

Check the html on the same page in your computer publishing program. If it is ok why not try to republish the site. If the file in your computer looks like the html I have posted above your computer has been hacked and not the website, redo the page and try to post it. - Tom

34 posted on 12/20/2004 8:13:08 PM PST by Capt. Tom (Don't confuse the Bushies with the dumb Republicans - Capt. Tom)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous
From: Google Groups

It is indeed a webworm, targetting the most recent vulnerabilities announced this past Friday in PHP. While I do automatic nightly updates of certain key components of my systems, this update was not yet released from my publisher. I misread their announcement, and so it is entirely my fault. If I had noticed they didn't intend to patch within 24 hours, I'd have hand-patched.

The primary purpose of this worm is to set up some sort of spam-gizmo. I have not yet completed analysis of the code, but it is Brazilian in origin and at initial glance seems to be trying to test email addresses for validity, keeping a list of good and bad email addresses. It then reported them back through IRC to someone who I assume is collecting the data in their master database to spam away using other (or possibly the same) drones. Though it would seem the folks who run Windows on their desktops are the most prone to the spam-sleepers. I guess that will teach them to trust Ol' Bill. ;)

52 posted on 12/21/2004 12:40:41 AM PST by kingu (Which would you bet on? Iraq and Afghanistan? Or Haiti and Kosovo?)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous

Information is flying across the lists about the worm that hit your site. It appears to be a worm that exploits a vulnerability in phpBB that was identified a month ago:


This bug only exploits a hole in phpBB2 as far as I can tell. It does not
appear to exploit a hole within PHP. In order to protect yourself, you
must upgrade phpBB2 to version 2.0.11.
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

See also:
http://isc.sans.org/

Generation 9 appears to overwrite files with the following extensions:
.htm, .php, .asp, .shtm, .jsp, .phtm

It only displays a defacement message saying

"NeverEverNoSanity WebWorm generation #"

Where # is the generation of the worm.


55 posted on 12/21/2004 12:44:09 PM PST by Prime Choice (Merry Christmas and a Happy New Year! ...And no, my powers can only be used for Good.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous; dimples1
Here's an article about the "Santy" worm: Net worm using Google to spread


58 posted on 12/22/2004 8:34:50 AM PST by KS Flyover
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Armedanddangerous; Prime Choice
If you need additional info about Santy Worm you should check here http://www.kb.cert.org/vuls/id/497400 . If you have a trace on the source (other than Google), I'm sure they would like to talk to you. By now its under control but you never know. I recognized the 'neverevernosanity' tag and thought, "Hey, we were talking about that one".
59 posted on 12/25/2004 5:43:18 PM PST by Splatter (A foolish man is able to learn, has the opportunity, and does not do it..)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson