I thought of you guys here when I found out about this today.
Leave it to Ziff Davis to use a cheap grocery store tabloid headline ploy by calling it a "Net worm using Google to spread" though.
What a joke and way off the point.
It is a hacking tool to automate the defacing PHP web sites and nothing else.
The tool just uses search engine results for a search of "Powered by PHPbb", it makes no difference what search engine, and it does not infect the search engine or even any sites it defaces and can't harm those that visit.
The hacker could just as easily deface any PHP site he finds.
Searching the net for something all of them contain just made for more targets is all.
ZDNet Claiming "Net worm using Google to spread" was assanine.
"PHP Bulleten Boards being found by search engines and trashed" would have been a much better headline I would think, because the millions of people that use Google are simply not affected and 99% could care less.
Details here:
http://news.zdnet.com/2100-1009_22-5499 ... ag=nl.e589
----
But much more info here:
http://isc.sans.org/diary.php?date=2004-12-21
"The worm exploits the 'highlight' bug in phpBB 2.0.10 and
earlier. The current version of phpBB (2.0.11, released Nov.
18th) fixes this problem."
To update the progress of the community supported
distributions progress on releasing a PHP update, Red Hat
has released updated rpms for FC2 and FC3 at the same
time as their enterprise products (well done), The Fedora
Legacy continues discussion for earlier Red Hat releases but
still nothing for FC1 (which should be a simple 4.3.3 to
4.3.10 upgrade). Debian still not available.
----
PHP is mainly a Unix type system script launguage.
Windows guys use VBscript (.asp) so few if any windows servers will be affected.
Glad to see that this was not the cause of your problem here.
Live long and prosper MTM2.com ;-}