New Worm Searches Google For Victims

CYBERSPACE — A new Internet worm discovered today uses popular search engine Google to find potential victims and has caused what antivirus firm Kaspersky calls an “epidemic.”

Net-Worm.Perl.Santy.a, which targets the phpBB online bulletin board software, apparently searches Google for “viewfiles.php” which reveals vulnerable versions of phpBB, then launches an attack on the site.

“Santy.a is something of a novelty,” Kaspersky said. “It creates a specially formulated Google search request which results in a list of sites running vulnerable versions of phpBB.”

Once the virus has located its targets and successfully infected a site, it searches for and overwrites files with .asp, .htm, .jsp, .php, .phtm, and .shtm extensions. In their place, the worm places files which contain the text, “This site is defaced!!! NeverEverNoSanity WebWorm generation.”

Original reports suggested that the worm was exploiting one of the major PHP vulnerabilities announced last week by the open-source group that distributes the programming language, but the Internet Storm Center recently stated that the exploit lies in the “highlight” feature in versions of phpBB earlier than 2.0.11.

The “highlight” exploit centers around an SQL injection bug that allows attackers to arbitrarily execute code.

A search using Microsoft’s search engine for text strings contained in infected files turned up approximately 40,000 sites at 11 a.m. on Tuesday. The same search conducted at 12:30 p.m. revealed 133,780 hits.

“Santy.a is spreading rapidly and has caused an epidemic,” Kaspersky stated. “However, this does not directly affect users. Although the worm infects websites, it does not infect computers used to view those sites.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FansRevenue Acquires DivaTraffic

FansRevenue has acquired web traffic service DivaTraffic.

AEBN Announces Peter Green as Top Male Boy/Girl Performer for Summer 2025

AEBN has revealed its top 10 male Boy/Girl performers for summer 2025, with Peter Green landing atop the leaderboard.

Spicey AI Relaunches Site, Debuts $Spicey Tokens

Interactive voice chat platform Spicey AI has relaunched its website and introduced $Spicey tokens.

FSC: Missouri Age Verification Rule Will Not Take Effect August 30

The Free Speech Coalition (FSC) announced that Missouri's proposed age verification legislation will not take effect on August 30, as it had originally estimated.

Little Caprice, Marcello Bravo to Co-Host 2025 XMA Europa Awards

XBIZ is pleased to announce that husband-and-wife duo Little Caprice and Marcello Bravo will co-host adult’s biggest night in Europe: the 2025 XMA Europa Awards on Sept. 4, in the epic climax to XBIZ’s fall events series.

Germany Will Block Payments to AV-Noncompliant Adult Sites as of Dec. 1

Starting Dec. 1, Germany will implement new rules prohibiting financial institutions from providing payment services to adult sites deemed to have inadequate age verification systems and making it easier for the government to target websites mirroring the content of such sites.

Jerkmate Joins Pineapple Support as Partner-Level Sponsor

Jerkmate has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

FSC Launches Age Verification Toolkit for Adult Websites

The Free Speech Coalition (FSC) announced today that it has launched a comprehensive toolkit to help adult websites navigate age verification laws.

Romero Mr. Alien to Present XBIZ Talk at Amsterdam Conference

XBIZ is pleased to announce that noted producer/director Romero Mr. Alien, the impresario of the XMAs award-winning studio Hentaied, will present an exclusive talk at next month’s Amsterdam conference.

New Fansly Analytics Platform 'SlyKiwi' Launches

SlyKiwi, a new analytics platform exclusively designed for Fansly content, has officially launched.

Show More