Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 07-08-2006, 06:53 PM   #1 (permalink)
In The Zone
 
rohan's Avatar
 
Join Date: Mar 2004
Location: Bangalore
Posts: 297
Default phpBB forums vulnerable to attack

Recently a bot using the name FuntKlakow, has been registering to at least hundreds (maybe thousands) of phpBB forums. It is susspected that the bot will take advantage of an exploit in phpBB froums, that might not be known yet. In other words the next time phpBB announces a critical vulnerability, the bot would have everything ready (just a post away) from attacking thousands of sites/forums.

The Defence

Best defence against these kinds of bot-members, might be setting up honeypot-forums, which the search engines can find but to which there are no permanent links from the web. When new bot-members are detected, such would be listed at each particular forum makers homepage.
When a bot would then try to register to a forum, the forum program would check the user/bot inputted user-name (or other characteristics) and if those would match to those catched by a honeypot-forums, registerin such user detais would be eliminated ( and possible IP banned for some time)

Source
__________________
If there wasn't greed, we still would have been single-celled organisms.
rohan is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 07-08-2006, 07:31 PM   #2 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,015
Default Re: phpBB forums vulnerable to attack

thanks for the info....
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 07-08-2006, 08:36 PM   #3 (permalink)
Google Bot
 
Pathik's Avatar
 
Join Date: Aug 2005
Posts: 9,751
Default Re: phpBB forums vulnerable to attack

yeah man... thx
Pathik is offline  
Old 07-08-2006, 09:39 PM   #4 (permalink)
In The Zone
 
damnthenet's Avatar
 
Join Date: Apr 2005
Location: Chennai
Posts: 221
Default Re: phpBB forums vulnerable to attack

Good info
__________________
Sony Xperia Neo V - Review and Discussion Thread:
http://www.thinkdigit.com/forum/mobi...ml#post1520514
damnthenet is offline  
Old 07-08-2006, 10:10 PM   #5 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,015
Default Re: phpBB forums vulnerable to attack

Quote:
Originally Posted by phpBB Support Team
that bot is very very old news Smile it is not hacking, it is nothing mre than a spam bot. First you need to make sure your boards are up to date, then stop guest posting and set account activation to at least "user". You will need to turn on Visual confirmation. If after doing this you find that some spambots are still getting through there are other changes you can make to stop them, alot of these methods are talked about in this topic

http://www.phpbb.com/phpBB/viewtopic.php?p=1404100
chill guys .... it seems that phpbb has it covered!!! ....phpbb rules
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 08-08-2006, 05:54 AM   #6 (permalink)
In The Zone
 
knight17's Avatar
 
Join Date: Oct 2005
Location: Kerala
Posts: 312
Default Re: phpBB forums vulnerable to attack

Avoid its registration using "images" while signig up..
I think you got the idea
__________________
"It's not a silly question if you can't answer it." Sophie's World [ http://en.wikipedia.org/wiki/Sophie's_World ]
knight17 is offline  
Old 08-08-2006, 10:05 AM   #7 (permalink)
In The Zone
 
rohan's Avatar
 
Join Date: Mar 2004
Location: Bangalore
Posts: 297
Default Re: phpBB forums vulnerable to attack

@knight17: hmm.. what's that called..... it's on my tounge.... ohh... yes... Image verification. That'll help.
__________________
If there wasn't greed, we still would have been single-celled organisms.
rohan is offline  
Old 08-08-2006, 06:55 PM   #8 (permalink)
In The Zone
 
nik_for_you's Avatar
 
Join Date: Apr 2004
Location: Paris
Posts: 313
Default Re: phpBB forums vulnerable to attack

nice info.. but i dont think this bot is dangerous !! what next after registering to forum ?
__________________
I AM REBEL
nik_for_you is offline  
Old 08-08-2006, 08:30 PM   #9 (permalink)
The Devil
 
blackpearl's Avatar
 
Join Date: Feb 2006
Location: 0x02AE88C6FF
Posts: 966
Default Re: phpBB forums vulnerable to attack

phpbb has got tons of vulnerablities.
blackpearl is offline  
Old 08-08-2006, 09:45 PM   #10 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,015
Default Re: phpBB forums vulnerable to attack

Quote:
Originally Posted by blackpearl
phpbb has got tons of vulnerablities.
.... which can b avoided if proper care is taken
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 08-08-2006, 09:52 PM   #11 (permalink)
In The Zone
 
Venom's Avatar
 
Join Date: Jun 2006
Posts: 240
Default Re: phpBB forums vulnerable to attack

Quote:
Originally Posted by nik_for_you
nice info.. but i dont think this bot is dangerous !! what next after registering to forum ?
What if it registers all possible nicks on your forum eh?
__________________
From now on we are poison to you, that's why we call ourselves, the Venom!
Venom is offline  
Old 11-08-2006, 02:11 PM   #12 (permalink)
In The Zone
 
nik_for_you's Avatar
 
Join Date: Apr 2004
Location: Paris
Posts: 313
Default Re: phpBB forums vulnerable to attack

thats right buddy.. I cnt give this nick to sillt bot
__________________
I AM REBEL
nik_for_you is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +5.5. The time now is 03:19 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2