Saturday, December 25, 2004


There is a worm that targets Wordpress that is flooding servers. It refers to and tries to run perl scripts. I noticed a huge increase in traffic today, and in an attempt to stem the flow, did a bit of searching. gives some tips.

The key is to stop the first probe that has a user-agent of "lwp-trivial". On my site it would grab one of the links and then attack it. If the first probe is stopped however, the worm quits.

There was one hit on the 3rd, 11th and 17th of December, then just before 9AM PST the flood started. 303 different servers did 25,569 hits with the worm. The worm changes the &version and appends a &cmd to the url found in the page it gets from the first probe. Here is the added portion of the url, with linebreaks for readability: "&version= &cmd=cd%20/tmp;;;;;; perl%20spybot.txt;perl%20worm1.txt; perl%20ownz.txt; perl%20php.txt"

The Wordpress support seemed to indicate that the worm checked whether Wordpress was running before initiating the attack. I don't run Wordpress, so it doesn't seem to matter. In other words most web servers will be generously donating bandwidth for nothing.

Informative blog. Check out my 42xs955 kde blog.
Nice KDE rlated blog. Visit my kde p50mrx1 blog.
website design bathurst I found your site looking for flash web site design and thought I'd just say Hi.
Hey, you have a great blog here! I'm definitely going to bookmark you!

I have a free shopping cart php script site/blog. It pretty much covers free shopping cart php script related stuff.

Come and check it out if you get time :-)
I commend your post on this one of a kind blog.

I hope you find my site useful containing christmas display information and content.
I just came across your blog about home shopping network and wanted to drop you a note telling you how impressed I was with the information you have posted here. I also have a web site about home shopping network so I know what I'm talking about when I say your site is top-notch! Keep up the great work, you are providing a great resource on the Internet here! If you get a chance, please stop by home shopping network
Yeah Wordpress rocks, I recently switched.. I'm trying to find a cool template that I like.. so far i like the one i have now - anyway, my blog's url is I've got a page rank of 4 [if you know anything about page ranks and search engine optimization] and 309 pages indexed in google.. unfortunately it isn't more than that...'ve got a great blog here! -Paul
Post a Comment

Subscribe to Post Comments [Atom]

<< Home

This page is powered by Blogger. Isn't yours?

Subscribe to Posts [Atom]