<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Thu, 23 May 2013 03:44:45 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Christopher Kunz's Blog: Mambo worm in the wild]]></title>
      <guid>http://www.phpdeveloper.org/news/4441</guid>
      <link>http://www.phpdeveloper.org/news/4441</link>
      <description><![CDATA[According to <a href="http://www.christopher-kunz.de/serendipity/archives/76-Mambo-worm-in-the-wild.html">this post</a> on <i>Christopher Kunz</i> today, there's a Mambo-targeted worm out "in the wild" called <a href="http://www.christopher-kunz.de/serendipity/exit.php?url_id=382&entry_id=76">Elxbot</a>.
<p>
<quote>
<i>
Well, it wasn't totally unexpected, I guess. The recently discovered remote code execution hole in Mambo has spawned a nifty little worm, called "<a href="http://www.christopher-kunz.de/serendipity/exit.php?url_id=382&entry_id=76">Elxbot</a>". I actually referred to the (then still fairly unknown) vulnerability and to the possibility that it might be abused by worm writers in my talk at the last PHP Conference.
<p>
I am already expecting a similar outbreak for the PHPKIT holes I recently reported. It has all of the features that I outlined above, although the install base is probably somewhat limited to german users (and there, mainly to gaming clans). Seeing this, I didn't actually publish a PoC for the remote code execution hole, but it is somewhat trivial to find and exploit anyway.
</i>
</quote>
<p>
<a href="http://www.outpost24.com/ops/delta/FrameIndex.jsp?page=/ops/delta/news/News.jsp%3FXID%3D1157%26XVCLANGUAGEID%3D">The worm</a> itself searches Google for available targets, infects the system, and connects to an IRC server where the controlling party is waiting. From there things like arbitrary command execution, TCP floods, HTTP floods, and Portscans can be made. For complete information, check out <a href="http://www.outpost24.com/ops/delta/FrameIndex.jsp?page=/ops/delta/news/News.jsp%3FXID%3D1157%26XVCLANGUAGEID%3D">this page</a> on the Outpost24.com site...]]></description>
      <pubDate>Tue, 06 Dec 2005 06:50:24 -0600</pubDate>
    </item>
  </channel>
</rss>
