Forum Moderators: rogerd
The first defacement we heard about happened today at around 15:00 GMT....---
If you try to search for defaced sites using the MSN Search Engine, you will see an enormous amount of sites that have been defaced by the Santy.A worm. Search using the following text string:
"This site is defaced!" NeverEverNoSanity....
At this moment the search finds tens of thousands defaced websites! It should be noted that some of the defaced sites have been restored already, but many are still defaced...
Further up the weblog, it seems to indicate that if you have all the latest patches, you should be safe.
If you don't have all the latest patches, then this looks dangerous.
It's all related to the vulnerbaility/patch that was discussed in this thread [webmasterworld.com], so everyone here is patched and not among the thousands of deface boards, right?
The Santy worm uses a flaw in the widely used community forum software known as the PHP Bulletin Board (phpBB) to spread... The worm searches Google for sites using a vulnerable version of the software, antivirus firm Kaspersky said in a statement.Almost 40,000 sites may have already been infected.After it has taken over a site, the worm deletes all HTML, PHP, active server pages (ASP), Java server pages (JSP), and secure HTML pages, and replaces them with the text, "This site is defaced! This site is defaced! NeverEverNoSanity WebWorm generation X," according to Kaspersky.
[news.zdnet.com...]
Around 6 million sites appear to be running the phpBB software, according to a search of Google for the phrase "Powered by phpBB"--an acknowledgment appended to the bottom of any site that uses the software.
6 million sites! That seems kinda high...
I just changed the footer on my forum to something like this:
Powered by phpBB Will that prevent my site from showing up in searches of "powered by phpbb"?
Will that prevent my site from showing up in searches of "powered by phpbb"?
Not sure, but consult the comment in the
overall_footer.tpl file for specific guidance. The reqest is to keep the link to the phpbb.com site in the "Powered by" line. However, I think that you would be entirely respecting the license in spirit as well as by the letter if you were to alter the phrase to something similar but differently-worded. Try "Built with phpBB", "Made with phpBB technology", "Forum software developed by the phpBB community". At worst, you could write it out with Javascript.
Bear in mind that the GPL license does not actually force you into keeping the phpBB link, but it is respectful to the community that built the product and it may affect your chances of getting technical support from them if you don't keep it.
In a similar vein, I've mentioned before about one of the advantages of using one of the SEO mods for phpBB which changes the filenames with mod_rewrite: a simple search for "viewtopic.php" gives you a long list of phpBB forums too, so if yours doesn't use that pattern, it helps stay under the radar.
The same goes for vBulletin and other such packages too: and many of them require specific copyright declarations which are much less flexible than for phpBB.
Quite true. Fortunately, the truly paranoid can pay a fee to allow removing the footer notices. I did this for one site earlier this year; it wasn't too costly compared to the other expenses of running a major forum.
I started a new thread in Web Gen on Removing Software Footprints [webmasterworld.com].
[google.com...]
Once they clean up they'll find that they have dupe penalties from Google too.
Todays diary at [isc.sans.org...] has this info:
According to [news.zdnet.com...] Google has deactivitated queries essential to Santy's propogation, which should lead to it's dying off.
The same search on beta.search.msn.com shows 131.635 hits.
Regards,
R.
An interesting side note to the whole thing:
The msn beta SERPS were consistently "ahead of the curve" as compared to google in terms of listing the number of boards hit.
MSN is crawling harder, right now, methinks.
Now, I haven't actually done it, because I managed to avoid having anything I'm involved with affected, but that seems to be the prevailing method of dealing with it, and I know of other people who've done this and had it fix the problem.