spacer

Welcome Guest ( Log In | Register )

> Posting Rules

Please read the Forum Rules before posting.

 
Digg this topic Save to del.icio.us Submit to Reddit Slashdot It
Reply to this topicStart new topic
> FuntKlakow, Something nasty?
Stefan100
post 19th March 2006, 6:48am
Post #1


Gone member
****

Group: Members
Posts: 123
Joined: May 2005
Member No.: 3,617



Read

Someone named "FuntKlakow" have been registering on thousands and thousands of forums in one day. what.gif I have no idea what this might be, but according to some it might be something nasty. So I just want to warn you all about this.
Go to the top of the page
 
+Quote Post
Zombie
post 19th March 2006, 7:05am
Post #2


Mr. Grognard
*****

Group: Admin
Posts: 2,862
Joined: January 2004
From: Sheboygan WI, USA
Member No.: 1,322



Thanks for the heads up, Stefan100! We'll keep an eye out and take action if necessary. smile.gif

Edit: This seems to be isolated only to phpBB forums and not IPB so we should be safe. There haven't been any recent members here with that IP either.

- Zombie


--------------------

QUOTE(JellyfishGreen)
Zombie: Empirical data's your only man, when formulating a research plan.
A soldier's death is never in vain if it makes the formula more plain.
A few dozen make a better case for refining that third decimal place.
They call me Zombie because I don't sleep, as I slowly struggle to climb this heap,
of corpses, data points, and trials, but from the top - I'll see for miles!
Go to the top of the page
 
+Quote Post
Accounting Troll
post 19th March 2006, 5:45pm
Post #3


Bridge troll
*****

Group: Admin
Posts: 1,057
Joined: October 2003
From: Wales
Member No.: 1,341



The information I found here suggests that the person behind this setting himself up to do something very nasty to phpBB forums next time a security flaw is discovered.

EDIT: FuntKlakow does sometimes post on forums, and his signatures advertise the sort of services one associates with junk email, so I suspect that its creator is spamming forums as an alternative to sending out junk email.

His posts have pretty much the same structure and are clearly automatically generated: example.

Incidentally, in the example I found, the person called Cepelin is clearly an alias of FuntKlakow. There also appears to be two FuntKlakows as the signatures are different.
Go to the top of the page
 
+Quote Post
Stefan100
post 19th March 2006, 6:27pm
Post #4


Gone member
****

Group: Members
Posts: 123
Joined: May 2005
Member No.: 3,617



eh.gif OK I searched this Cepelin with google, and guess what? Almost as many findings as with FuntKlakow... Guess this hacker have several bots. hmm.gif

And it just struck me, that if this hacker have several bots, some might be able to register on other forums than just phpBB ones.
Go to the top of the page
 
+Quote Post
Zombie
post 20th March 2006, 3:43am
Post #5


Mr. Grognard
*****

Group: Admin
Posts: 2,862
Joined: January 2004
From: Sheboygan WI, USA
Member No.: 1,322



As I said before, that user only seems interested in taking advantage of the flaws in phpBB forums. He/it could register at an IPB forum, but intricate knowledge of that particular software would be needed to abuse those faults.

As far as I can tell, there can only be one member with the same username in a phpBB forum. See here (search by username and ascending order). Its just that signatures in posts are probably not updated when the user changes the sig.

It is only speculation what the intentions of this bot are. Exploiting vulnerabilities in phpBB forum software may be one. Using those forums as a way to spam via a signature seems to be the primary focus at this point.

This being said, the IP is known so any attempt by this bot to register here will be quickly acted upon. smile.gif

- Zombie


--------------------

QUOTE(JellyfishGreen)
Zombie: Empirical data's your only man, when formulating a research plan.
A soldier's death is never in vain if it makes the formula more plain.
A few dozen make a better case for refining that third decimal place.
They call me Zombie because I don't sleep, as I slowly struggle to climb this heap,
of corpses, data points, and trials, but from the top - I'll see for miles!
Go to the top of the page
 
+Quote Post
Bomb Bloke
post 23rd March 2006, 6:28am
Post #6


The Smily Admin
*****

Group: Admin
Posts: 2,999
Joined: September 2002
From: Tasmania (AU)
Member No.: 152



It seems bots are quite adept at posting on boards if guest posting is allowed. It's relatively unusual for them to register.

The thing that confuses me is, why register on all the boards unless he's planning on doing something to them NOW? If he just leaves all those registrations out there, that's plenty of time for admins to cotton on, and by the time he's got a flaw to exploit his IP will be blocked all around the web.

My guess is that he's setting up a spam network, or just looking for boards where the mods aren't paying attention.


--------------------
BB's X-Com Projects Page
You're just jealous 'cause the voices only talk to me :P
We love Tammy! :)
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Lo-Fi Version Time is now: 2nd December 2008, 5:18am