ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Google stops spread of Santy worm

Munir Kotadia ZDNet Australia

Published: 22 Dec 2004 09:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has responded to calls from antivirus companies to stop the advance of an Internet worm that was using the search engine's technology to spread among online bulletin boards.

Antivirus companies say the Santy worm, which searches Google for sites that use a vulnerable version of the phpBB bulletin board software, is spreading quickly - it had already infected about 40,000 Web sites by Tuesday evening.

On Wednesday, a Google representative told ZDNet Australia that though Google users were not at risk from Santy, the search company had started blocking attempts by the worm to replicate.

"We are aware of an Internet worm that exploits a vulnerability in third-party Web servers that use PHP bulletin board software. While the worm does not put Google users at risk, we are working to help stop its propagation by blocking queries to Google that are generated by the worm," the representative said.

Google was prompted into action after antivirus companies, such as F-Secure, said it would be a "trivial" effort for Google to stop the spread of the worm because its methods of propagation were well-known.

"We've been trying to reach the right people at Google," said Mikko Hypponen, research director of antivirus company F-Secure. "They could stop this Santy outbreak right now simply by stopping responding to the queries the virus uses. This wouldn't hurt any end users and would in fact take a load off Google servers."

In August, a MyDoom variant used Google and other search engines to hunt for email addresses. The virus pumped so many queries into Google that the search engine was unavailable or very slow for large periods of time. The same variant of MyDoom also succeeded in knocking a number of smaller search engines -- including Lycos and AltaVista -- off the Web completely.

ZDNet Australia's Munir Kotadia reported from Sydney. For more coverage from ZDNet Australia, click here. CNET News.com's Robert Lemos contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
64 out of 131 people found this useful


Full Talkback thread

1 comment

  1. this is cool man , keep on truckin Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment