The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.
|
 |
|
Dev Shed Forums
> System Administration
> Antivirus Protection
|
Is this 'PHP Virus' article a joke??
Discuss Is this 'PHP Virus' article a joke?? in the Antivirus Protection forum on Dev Shed. Is this 'PHP Virus' article a joke?? Antivirus Protection forum discussing issues relating to antivirus programs, spyware, hijack protection, and personal firewalls for all operating systems. Keep your systems protected from hackers and other hazards.
|
|
 |
|
|
|
|

Dev Shed Forums Sponsor:
|
|
|

January 11th, 2001, 01:01 PM
|
|
Junior Member
|
|
Join Date: Jan 2001
Posts: 7
Time spent in forums: < 1 sec
Reputation Power: 0
|
|
|

January 12th, 2001, 05:31 AM
|
|
Member
|
|
Join Date: Sep 2000
Location: Colchester, England
Posts: 131
Time spent in forums: 1 m 8 sec
Reputation Power: 13
|
|
If you read the key elements it only affects Windows:
"When it executes, PHP.NewWorld looks for php, hm, html or htt suffix files in the C:Windows directory. All files found with these extensions will become infected."
"When a user executes a dot.php file, Central Command says, the virus body will be executed from an external file and will take full control."
Usually when a warning states that the virus is going take full control or wipe your hard disk, or all files will become infected it is a hoax.
Also the whole article seems a bit weak on details. The article states that the problem is on the server and makes no mention of propogating through to a client. When running anything on Windows you should be cautious of running any new code of unknown origin.
http://www.symantec.com have a database of most known viruses and hoaxes, yet they haven't got anything related to php.newworld yet.
I know I haven't answered the question but hopefully given you some useful info.
Andy J
|

January 12th, 2001, 02:08 PM
|
|
Junior Member
|
|
Join Date: Jan 2001
Location: Los Angeles
Posts: 5
Time spent in forums: < 1 sec
Reputation Power: 0
|
|
Well I would not give this any credit whatsoever.
I also think that technical articles should be written by the technicaly literate.
I think someone is trying to sell some virus software.
This article does not point out the fact that php installed as a CGI or helper application to your web server executes under your webservers permission settings. This would rule out access to any directory not directly allowed by your webserver settings docroot.
Who would have any php, html files in there windows directory anyway?
I would and could go on and on , but rule of thumb is that a real hack would provide a spoof kit and the related code to verify the claims and results, this is the norm.
This is a sure Hoax to sell some sub standard virus software to newbies.
The only way for this to even work would be for a user to download the PHP file to their system and install to the executable script directory, from there it would then have to be called. This is how all of your other scripts work too, so now we also need to have scripts in the windows directory, oops we dont and the web server will not execute scripts outside its control so now what?
You get the idea.
|

January 12th, 2001, 08:10 PM
|
|
Junior Member
|
|
Join Date: Jan 2001
Posts: 1
Time spent in forums: < 1 sec
Reputation Power: 0
|
|
REEEE TARRRR TEDDDDD
I just checked the websites in question. Here's the scoop
- Steve Gold, Newsbytes writes (as if it were a real story) an article which is basically a shameless regurgitation of someone else's technically lacking press release. He reports on a company called Command Central, which can be found at AVS.com, that has detected (and already remedied!) a virus so-called PHP.NewWorld. You have to go there and read it for yourself. Its a hoot! He even gets the syntax of the request method mispelled.
For one thing, .php and .html files are never executed in any case. They may be parsed or interpreted, but never executed - especially on a Windows machine. Who would ever be parsing .php scripts on a Winblows??
Foolishness. Foolishness.
|
Developer Shed Advertisers and Affiliates
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Rate This Thread |
Linear Mode
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|