Original URL: http://www.channelregister.co.uk/2006/09/07/wiki_exploit/
Hackers are exploiting vulnerabilities in wiki software packages to establish networks of compromised computers.
Software bugs in Pmwiki and Tikiwiki software applications are being actively used to create botnets, the SANS Institute's Internet Storm Centre reports (http://isc.sans.org/diary.php?storyid=1672).
It reckons the exploits in Tikiwiki 1.9 (and below) and Pmwiki version 2.1.19 (and below) are the work of the same virus writer. Both Tikiwiki and Pmwiki are software packages that allow the creation of wikis - web applications that allow surfers to easily add, remove, or edit the content of collaborative websites.
The Pmwiki exploit can only be exploited where the "Register_globals" attribute is enabled. However, the Tikiwiki exploit can be exploited regardless of this setting.
As well as loading an IRC bot that connects to different channels to access to Undernet IRC servers, attackers are also loading a variety of other exploits and attack tools on the compromised machines. Alongside Perl flood scripts, useful for launching denial of service attacks, exploits for both 2.4 and 2.6 Linux kernels are also being loaded onto vulnerable machines.
Pmwiki users are advised to upgrade (http://www.pmwiki.com/wiki/PmWiki/ReleaseNotes) to guard against attack. Tikiwiki has published an advisory (http://tikiwiki.org/tiki-read_article.php?articleId=136) explaining a workaround designed to guard against attack, pending the availability of software patches. ®
FBI logs its millionth zombie address (13 June 2007)
http://www.channelregister.co.uk/2007/06/13/millionth_botnet_address/
Trend Micro to kick butt on botnets (26 September 2006)
http://www.channelregister.co.uk/2006/09/26/trend_micro_botnet_appliance/
Web vulns top security threat index (18 September 2006)
http://www.channelregister.co.uk/2006/09/18/web_vulnerabilties/
Readers battle botnets for control of planet Earth (21 April 2006)
http://www.theregister.co.uk/2006/04/21/letters/
Web 2.0 worm downs MySpace (17 October 2005)
http://www.channelregister.co.uk/2005/10/17/web20_worm_knocks_out_myspaces/
Grid technology stalls Wiki vandals (22 September 2005)
http://www.theregister.co.uk/2005/09/22/grid_wiki_vandal/
© Copyright 2008