As the F-Secure blog reports, there is an exploit for the older PEAR::XML_RPC vulnerability (as reported by the GulfTech Security, the Hardened-PHP Project et al.) in the wild, and it seems to be a worm. Although this does not really come as a surprise, the surprising fact is that the F-Secure guys state not to have received many reports yet.
The ISC has some more facts: it seems that the worm is targetting the following paths:
/phpgroupware/xmlrpc.php
/wordpress/xmlrpc.php
/b2evo/xmlsrv/xmlrpc.php
/b2/xmlsrv/xmlrpc.php
/blogtest/xmlsrv/xmlrpc.php
/blog/xmlsrv/xmlrpc.php
/blogs/xmlsrv/xmlrpc.php
/blogs/xmlrpc.php
/community/xmlrpc.php
/drupal/xmlrpc.php
/blog/xmlrpc.php
/services/xmlrpc.php
/xmlsrv/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlrpc.php
I’d bet with that attack vector, there is still a five-figure number of vulnerable servers out there... Funny though, that the old hole is targetted, and not the new one.
Anyway, off to the conference now. See y’all soon.