This worm is written in Perl. It's searching vulnerable forum sites via Google. When a suitable site is found, the worm uses a remote exploit to gain access to it, defaces it and restarts random scanning for new hosts.</p><p align="justify">There has been several
serious holes in the phpBB software over the years. One was discussed
in Netcraft just days ago.</p><p align="justify">We don't know how many phpBB sites there are in the world, but Google search for
inurl:phpbb inurl:viewtopic gives over a million hits...</p><p align="justify">The first defacement we heard about happened today at around 15:00 GMT.</p><p align="justify">Official
home page of phpBB does not mention this incident yet.
On 21/12/04 At 03:46 PM</p>
Read more...