Forum Moderators: rogerd

Message Too Old, No Replies

phpbb and FuntKlakow

hype or real threat?

         

linear

9:52 pm on Mar 20, 2006 (gmt 0)

10+ Year Member



There's a lot of buzz around a supposed botnet threat relating to the FuntKlakow userid that has registered on lots of phpbbs around. But I have yet to read anything credible that rises above FUDmongering.

Anyone here have good threat assessment?

It's showing up in usually credible sources like Netcraft News and Information Week's RSS feed, but I have yet to read anyhitng more specific than the statement that some German site implied that the next time there's a critical vulnerability announced, we all better look out.

And I'm not sure how "botnet" figures into this, other than a cool-sounding buzzword to inject some excitement into headlines.

Added for clarity: InformationWeeks headline cries "Bot Herders Ready Attack Against Message Forums" and starts off with the sentence "Botnet controllers may be planning a large-scale attack against message forums, TechWeb has learned."

JollyK

5:31 pm on Mar 21, 2006 (gmt 0)

10+ Year Member



FuntKlakow also posts, along with another "user" named Cepelin who/which was registering about the same time. Usually, generic things like "I couldn't have said that better" and "I agree completely" which could be reasonable responses to almost anything. In the sig are links to anonymous proxy and "get traffic" sites.

The email address used by FuntKlakow, from what I've been able to determine, is not valid, so if you require email verification, then the bot won't be activated. I'm not sure about the one used by Cepelin. It looks like it might be a reasonable address, but it's in Poland, so I don't know for sure. On my forum, neither Cepelin nor FuntKlakow were activated, as I require email verification on registering.

There is a lot of speculation that the bots are registering to take advantage of an as-yet-undiscovered vulnerability in PHPbb, but so far, to me, it just looks like yet another "get free link popularity by registering on thousands of boards with the link in your sig" kind of ploy. I put word filters in my PHPbb for the site names in the sigs so at least those sites won't get free popularity off of me.

I'm not particularly worried about an attack from this, other than maybe a mass link spam attack.

JK

rogerd

6:07 pm on Mar 21, 2006 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



>> a mass link spam attack

Flood control will help if there are only a few userIDs involved.

kamikaze Optimizer

4:05 am on Apr 4, 2006 (gmt 0)

10+ Year Member



A simple fix is to register those names yourself, then make them not active. That is what I did.