Lyoko Freak: 2005 - 2015. Return to the past now....

It is currently Fri Jun 06, 2025 2:37 pm

To All PHPbb Forum Owners!!!!

For discussion of computers and the Internet, as well as a place for you to post your websites to gain more traffic.

Moderators: The Administrators, Moderators


To All PHPbb Forum Owners!!!!

Postby jeremy » Sun Apr 09, 2006 9:12 pm

"phpBB mass-hack being prepared (FuntKlakow-bot)?- general countermeasures
During the last few days a bot using a name FuntKlakow, has been
registering to at least hundreds (maybe thousands) of phpBB forums.

http://www.google.com/search?hl=com&q=F ... tnG=Hae&me ta=

Bot is also capable for posting to forums:
http://forum.uebimiau.org/search.php?se ... =FuntKlako w
http://www.alternativ.ro/forum/search.p ... uthor=Funt Klakow

But most on most forums the bot keeps silent.

Ok, what is a danger?
Next time the phpBB announces a critical vulnerability, the bot would
have everything ready (just a post click away) from attacking
thousands of sites/forums.

Best defence against these kinds of bot-members, might be setting up
honeypot-forums, which the search engines can find but to which there
are no permanent links from the web. When new bot-members are
detected, such would be listed at each particular forum makers
homepage.

When a bot would then try to register to a forum, the forum program
would check the user/bot inputted user-name (or other characteristics)
and if those would match to those catched by a honeypot-forums,
registerin such user detais would be eliminated ( and possible IP
banned for some time)

Juuso Hukkanen"
Image
User avatar
jeremy offline
New Kid
New Kid
 
Posts: 38
Joined: Sat Apr 08, 2006 2:13 pm

Postby Overcaffeinated Sloth » Sun Apr 09, 2006 9:44 pm

Didn't you already make a thread about this?

Overcaffeinated Sloth offline
 

Postby jeremy » Sun Apr 09, 2006 10:36 pm

Yes, I think this thread deserves to be double posted! ALOT OF PEOPLE ON THIS FORUM HAVE PHPBB FORUMS. I think they all have a right to know in fact I think this post should be stickied!
Image
User avatar
jeremy offline
New Kid
New Kid
 
Posts: 38
Joined: Sat Apr 08, 2006 2:13 pm

Postby Overcaffeinated Sloth » Sun Apr 09, 2006 10:47 pm

Even thought it's breaking the rules?

But you can always ask Erynn to post this in Site news, where it could definately be stickied.

Overcaffeinated Sloth offline
 

Postby Mewberries151 » Sun Apr 09, 2006 10:50 pm

I took care of it, Angelbolt. The one in Site Discussion has been locked.

Jeremy, regardless of your good intentions, posting a topic twice is still needless and spamish. People will see your topic. Believe me, forum owners that are at LF likely check Tech Discussion often. :)

Please don't make double topics though again, regardless of the situation or the intention. It is still spam and the action of creating spam completely negates the help you're trying to give.

The warning is appreciated but, please, don't double post, alright? ;)
"Hey, make up your mind. Am I a genius or a creep?"
"You're a creepy genius."

-Odd and Jeremie; "Cruel Dilemma", Code Lyoko

Icon made by boxofdoomage @ LJ

Image
Image
User avatar
Mewberries151 offline
Site Admin
Site Admin
 
Posts: 4380
Joined: Mon Jun 13, 2005 7:14 pm
Location: Rainbow Cloud ^_^

Postby Overcaffeinated Sloth » Sun Apr 09, 2006 10:52 pm

KK!

But I still express my opinion, I feel this is very bad, and thank you for this, as I was thinking ofbecoming my own phpBB owner myself, but now i'm second guessing it.

Overcaffeinated Sloth offline
 

Postby Evil Jeremy » Mon Apr 10, 2006 2:38 pm

oh dear. one of my forums is already infected. i dont understand how to fix it. can someone please give me a better discription?
User avatar
Evil Jeremy offline
Friend of Team Lyoko
Friend of Team Lyoko
 
Posts: 243
Joined: Sun Dec 25, 2005 8:47 pm

Postby jeremy » Mon Apr 10, 2006 2:43 pm

Better fix that Evil!

I wont double post again, just trying to be a helpfull member :no:
Image
User avatar
jeremy offline
New Kid
New Kid
 
Posts: 38
Joined: Sat Apr 08, 2006 2:13 pm

Postby Evil Jeremy » Mon Apr 10, 2006 2:52 pm

but i dont understand the way to get rid of it at all! can somebody help me please? also, the bot-user said things like "I agree with that" and "couldnt of said it better". was it programed to say that?
User avatar
Evil Jeremy offline
Friend of Team Lyoko
Friend of Team Lyoko
 
Posts: 243
Joined: Sun Dec 25, 2005 8:47 pm

Postby jeremy » Mon Apr 10, 2006 9:50 pm

I would start by removing user FuntKlakow, then double checking your data base and removing anything associated with FuntKlakow
Image
User avatar
jeremy offline
New Kid
New Kid
 
Posts: 38
Joined: Sat Apr 08, 2006 2:13 pm

Postby darktemplar » Tue Apr 11, 2006 2:11 am

Can I just deny creating user with name FuntKlakow and prevent bot attack?
Darktemplar is Back

Now doing: eee... something that looks and talks like a forum!
User avatar
darktemplar offline
Jeremie's Assistant
Jeremie's Assistant
 
Posts: 401
Joined: Thu Mar 23, 2006 3:13 pm
Location: New Antioch, Shakuras


Who is online

Users browsing this forum: No registered users and 2 guests