BugTraq
RE: phpBB Worm Dec 23 2004 08:28PM
Ofer Shezaf (Ofer Shezaf breach com) (1 replies)
RE: phpBB Worm Dec 25 2004 04:49AM
Chris Ess (securityfocus cae tokimi net)
> eval{
> while(my @a = getpwent()) { push(@dirs, $a[7]);}
> };
>
> push(@dirs, '/ ');

[...]

> Additionally, on Windows the worm would affect files on a single disk.

In generation 9 of the worm, there is the following code after what you
include:

for my $l ('A' .. 'Z') {
push(@dirs, $l . ':');
}

What I get out of this is that the worm should try iterating down every
available drive on a Windows server. I haven't tested this on a Windows
machine running ActivePerl yet though.

Sincerely,

Chris Ess
System Administrator / CDTT (Certified Duct Tape Technician)

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus