A new worm that seems to attack the vulnerability exploited by Santy has appeared, according to F-Secure's excellent blog, which I cannot recommend enough. Apparently, this worm patches the vulnerability that Santy opens. The worm then drops secure.php which looks like this:

Like most “good worms,” this one has a major side effect: it can crash sites it attempts to infect that are already patched with a ton of requests, and the patch itself might very well not work well.
More on this threat when it gets a name to it.
Posted
Dec 31 2004, 05:57 PM
by
trafton