|
| Author |
Message |
spaceman
Joined: 01 Mar 2006
Posts: 5
Location: UK
|
Posted: 3/17/2006, 3:31 pm Post subject: FuntKlakow |
|
|
Got a user of this name? One such has just registered on mine. I was a bit suspicious as the board is new and the name so unusual so I tried googling it. 1 of the results I got was:
http://www.gyptis.org/modules.php?name=Newsportal&op=article&id=21061&group=comp.security.misc
| Quote: |
During the last few days a bot using a name FuntKlakow, has been
registering to at least hundreds (maybe thousands) of phpBB forums.
...
Ok, what is a danger?
Next time the phpBB announces a critical vulnerability, the bot would
have everything ready (just a post click away) from attacking
thousands of sites/forums. |
Any ideas how to respond? _________________ http://lotusmatrix.net |
|
| Back to top |
|
 |
Ex0dus
Joined: 26 Sep 2005
Posts: 235
Location: Zarasu, Lithuania
|
Posted: 3/17/2006, 5:20 pm Post subject: |
|
|
If it really is such a danger, just delete it =/
Then start taking all kinds of bot preventive measures to protect yourself from bots in general. I dont have this one on my forum =/
-Ex0dus |
|
| Back to top |
|
 |
Truestar
Moderator
Joined: 10 Sep 2005
Posts: 738
Location: New York, United States
|
Posted: 3/17/2006, 6:50 pm Post subject: |
|
|
area51.phpbb.com was talking about this, almost every reply was an admin with this guy registered. I also have him on my board.
Do bots post? Because this guy does.
Oh well, time to delete him!  _________________ Truestar
Xbox Live: xTruestarx
Visit phpBBhacks.com for your phpBB templates, graphics, and modifications
Visit ManagingCommunities.com for tips on running a forum. Get advice from site management to the politics of running a forum. |
|
| Back to top |
|
 |
Niksa
Joined: 26 Dec 2005
Posts: 27
Location: Iowa
|
Posted: 3/22/2006, 1:51 am Post subject: |
|
|
I'd delete him.
Everything I've read shows it's bad news. Supposedly a bot that has over 40k registrations. Apparently waiting for the "next huge phpbb exploit". :/ |
|
| Back to top |
|
 |
Ex0dus
Joined: 26 Sep 2005
Posts: 235
Location: Zarasu, Lithuania
|
Posted: 3/22/2006, 6:01 am Post subject: |
|
|
We may not have to wait too much longer on that one. One of my users reported that his forum got hacked and the only registered user on it besides him was the bot known as funtklakow.
While its not definitive proof that it is working to break into a board or that it was successful, it is quite unnerving. He reported this just hours after the post here about it.
My personal advice is to disallow the name. This should act as a pre-emptive ban on the user. Of course you should set at least e-mail verification on as well and in general tune up your security settings. Those are just the steps i took though ^_^
-Ex0dus _________________ The home of the Sv2 Network Forums and MetaBB! |
|
| Back to top |
|
 |
dojo
Joined: 03 Sep 2005
Posts: 287
Location: Romania, Timisoara
|
Posted: 3/25/2006, 5:13 pm Post subject: |
|
|
Got it on my movies forums. Then I read about this in a webmaster forum, deleted the user and warned my people in my own webmaster forum to keep a close eye on it _________________ Webmaster articles, tutorials and topics |
|
| Back to top |
|
 |
Niksa
Joined: 26 Dec 2005
Posts: 27
Location: Iowa
|
Posted: 3/28/2006, 1:53 am Post subject: |
|
|
| For the people who have him on your forum, do you have Visual Confirmation on? |
|
| Back to top |
|
 |
Truestar
Moderator
Joined: 10 Sep 2005
Posts: 738
Location: New York, United States
|
Posted: 3/28/2006, 6:37 am Post subject: |
|
|
I believe I did, yes. _________________ Truestar
Xbox Live: xTruestarx
Visit phpBBhacks.com for your phpBB templates, graphics, and modifications
Visit ManagingCommunities.com for tips on running a forum. Get advice from site management to the politics of running a forum. |
|
| Back to top |
|
 |
Thoul
Joined: 14 Sep 2005
Posts: 169
|
Posted: 3/28/2006, 2:29 pm Post subject: |
|
|
I've gotten a couple of bots registering on my forum this week that somehow bypassed my visual confirmation, too. They weren't FuntKlakow, but one of them did try to spam my forum. It only failed because the bot accounts were set to use themes_id 1 (subSilver), which is not present on my forum. _________________ Phantasy Star: The Fringes of Algo | phpBB Smith |
|
| Back to top |
|
 |
Ex0dus
Joined: 26 Sep 2005
Posts: 235
Location: Zarasu, Lithuania
|
Posted: 3/31/2006, 2:26 pm Post subject: |
|
|
If yorue talking about the default phpbb visual confirmation, it is now pretty easily breakable by bots. Thus I am changing the visual confirmation (among other things) in the next edition of my forum. I am going to be using this visual confirmation. The ponly problem with it that sometimes its so hard to read that not even people can figure out what the letters are ^_<
-Ex0dus _________________ The home of the Sv2 Network Forums and MetaBB! |
|
| Back to top |
|
 |
|