Please read the Forum Rules before posting.
![]() ![]() |
19th March 2006, 6:48am
Post
#1
|
|
|
Gone member ![]() ![]() ![]() ![]() Group: Members Posts: 123 Joined: May 2005 Member No.: 3,617 |
Read
Someone named "FuntKlakow" have been registering on thousands and thousands of forums in one day. |
|
|
|
19th March 2006, 7:05am
Post
#2
|
|
![]() Mr. Grognard ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 2,862 Joined: January 2004 From: Sheboygan WI, USA Member No.: 1,322 |
Thanks for the heads up, Stefan100! We'll keep an eye out and take action if necessary.
Edit: This seems to be isolated only to phpBB forums and not IPB so we should be safe. There haven't been any recent members here with that IP either. - Zombie -------------------- QUOTE(JellyfishGreen) Zombie: Empirical data's your only man, when formulating a research plan. A soldier's death is never in vain if it makes the formula more plain. A few dozen make a better case for refining that third decimal place. They call me Zombie because I don't sleep, as I slowly struggle to climb this heap, of corpses, data points, and trials, but from the top - I'll see for miles! |
|
|
|
19th March 2006, 5:45pm
Post
#3
|
|
![]() Bridge troll ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1,057 Joined: October 2003 From: Wales Member No.: 1,341 |
The information I found here suggests that the person behind this setting himself up to do something very nasty to phpBB forums next time a security flaw is discovered.
EDIT: FuntKlakow does sometimes post on forums, and his signatures advertise the sort of services one associates with junk email, so I suspect that its creator is spamming forums as an alternative to sending out junk email. His posts have pretty much the same structure and are clearly automatically generated: example. Incidentally, in the example I found, the person called Cepelin is clearly an alias of FuntKlakow. There also appears to be two FuntKlakows as the signatures are different. |
|
|
|
19th March 2006, 6:27pm
Post
#4
|
|
|
Gone member ![]() ![]() ![]() ![]() Group: Members Posts: 123 Joined: May 2005 Member No.: 3,617 |
And it just struck me, that if this hacker have several bots, some might be able to register on other forums than just phpBB ones. |
|
|
|
20th March 2006, 3:43am
Post
#5
|
|
![]() Mr. Grognard ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 2,862 Joined: January 2004 From: Sheboygan WI, USA Member No.: 1,322 |
As I said before, that user only seems interested in taking advantage of the flaws in phpBB forums. He/it could register at an IPB forum, but intricate knowledge of that particular software would be needed to abuse those faults.
As far as I can tell, there can only be one member with the same username in a phpBB forum. See here (search by username and ascending order). Its just that signatures in posts are probably not updated when the user changes the sig. It is only speculation what the intentions of this bot are. Exploiting vulnerabilities in phpBB forum software may be one. Using those forums as a way to spam via a signature seems to be the primary focus at this point. This being said, the IP is known so any attempt by this bot to register here will be quickly acted upon. - Zombie -------------------- QUOTE(JellyfishGreen) Zombie: Empirical data's your only man, when formulating a research plan. A soldier's death is never in vain if it makes the formula more plain. A few dozen make a better case for refining that third decimal place. They call me Zombie because I don't sleep, as I slowly struggle to climb this heap, of corpses, data points, and trials, but from the top - I'll see for miles! |
|
|
|
23rd March 2006, 6:28am
Post
#6
|
|
![]() The Smily Admin ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 2,999 Joined: September 2002 From: Tasmania (AU) Member No.: 152 |
It seems bots are quite adept at posting on boards if guest posting is allowed. It's relatively unusual for them to register.
The thing that confuses me is, why register on all the boards unless he's planning on doing something to them NOW? If he just leaves all those registrations out there, that's plenty of time for admins to cotton on, and by the time he's got a flaw to exploit his IP will be blocked all around the web. My guess is that he's setting up a spam network, or just looking for boards where the mods aren't paying attention. -------------------- |
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 2nd December 2008, 5:18am |