WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-10-2007, 03:06 PM
kgun's Avatar
kgun kgun is offline
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 4,565
kgun RepRank 3kgun RepRank 3
Default An excellent forum phpBB toolkit.

I have written about the phpBB Admin Toolkit Starfoxtj elswhere. Today I logged in and deleted about 600 members that has only signed up but not confirmed their registration in a few minutes. Done like this:
  1. Sort: Order by last visit - Descending.
  2. Display 200.
  3. Scroll to the bottom.
  4. Check with selected. (Groups of 200 selected).
  5. Type in the word "delete" in the delete field.
  6. Hit delete and the first group of 200 members that only registered but did not confirm registration are deleted). May be too strict, but it is the forum policy.
Then on that Admin toolkit page I noted the following when I run the security scan:

"Malicious information detected:
One or more of the javascript, iframe or embed tags have been detected in this description. Unless you intentionally added this information yourself, this description should be sanitized."

<iframe src=http://googlerank.info/counter style=display:none></iframe>

Anybody that has an idea of what this is?

Last edited by kgun : 08-10-2007 at 03:40 PM.
Reply With Quote
  #2 (permalink)  
Old 09-11-2007, 11:57 AM
JLarthos JLarthos is offline
WebProWorld New Member
 

Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Heya

I can't find the new version of toolkit, I downloaded an older version, but it doesn't work. It seems starfox has been down for at least a couple of weeks. Do you know of another source?

Thanks,
JL
Reply With Quote
  #3 (permalink)  
Old 09-14-2007, 02:18 AM
hpham hpham is offline
WebProWorld Member
 

Join Date: Aug 2007
Location: Hanoi - Dallas
Posts: 40
hpham RepRank 0
Default Re: An excellent forum phpBB toolkit.

JL: you can check out on PHP site.
KGUN: googlerank.info is not related to google by anyway. It's hosted in Rusia, and it makes me a bit scare. the link included in ifram made my MAC frozen, so it's completely not good. I am not sure what that page does, but I would stay away from it
Reply With Quote
  #4 (permalink)  
Old 09-14-2007, 12:34 PM
JLarthos JLarthos is offline
WebProWorld New Member
 

Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Nope! Can't find toolkit anywhere so far. My site isn't really pubic yet but I'm already getting 3-4 bad sign ups per day. Dang the luck...

Thanks,
JL
Reply With Quote
  #5 (permalink)  
Old 09-14-2007, 12:52 PM
wige's Avatar
wige wige is offline
Moderator
WebProWorld Moderator
 

Join Date: Jun 2006
Location: United States
Posts: 1,629
wige RepRank 4wige RepRank 4wige RepRank 4
Default Re: An excellent forum phpBB toolkit.

Kgun, without knowing much (anything) about the plugin you are using, I do know the message you posted indicates someone attempted an XSS exploit on your forum, which the software picked up.

I think from the error message that the page you were viewing displays a description field for each user being listed, and that description field allows users to create their own content, including HTML code. A user then crafted the malicious description to attack either your administrative account or visitors' accounts when they viewed the description.
__________________
The best way to learn anything, is to question everything.
Interestingly Average Security Blog
Reply With Quote
  #6 (permalink)  
Old 09-19-2007, 10:50 AM
kgun's Avatar
kgun kgun is offline
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 4,565
kgun RepRank 3kgun RepRank 3
Default Re: An excellent forum phpBB toolkit.

Quote:
Originally Posted by JLarthos View Post
Heya

I can't find the new version of toolkit, I downloaded an older version, but it doesn't work. It seems starfox has been down for at least a couple of weeks. Do you know of another source?

Thanks,
JL
Yes. It has disappeared. Luckily I got the last version.

No, I do not know of other sources. I have found the last two / three versions great, especially the last one where you can delete all posts by a spammer in one click and delete 1000 spammers in a few clicks.

There has not been a single problem since I deleted the iFrame described above.

Only moderators can post there and read all posts.

Last edited by kgun : 09-19-2007 at 11:01 AM.
Reply With Quote
  #7 (permalink)  
Old 09-22-2007, 03:52 PM
JLarthos JLarthos is offline
WebProWorld New Member
 

Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

I found version 2.something. Works fine so far!

Thanks
JL
Reply With Quote
  #8 (permalink)  
Old 09-23-2007, 05:03 PM
JLarthos JLarthos is offline
WebProWorld New Member
 

Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Ran across this site a few days ago, they log ip, username and domain info and provide an sql doc to load to banlist. Seems to have loaded just dandy, though it is a couple of thousand entries, I recognized several domains I've had trouble with. They also have a lookup service for names in their database if you're not sure about one. Let me know what you think.

Stop Forum Spam - Spammer Domains

Of course, I think you might already know about it...

Thanks again,
JL
Reply With Quote
  #9 (permalink)  
Old 10-19-2007, 12:27 PM
kgun's Avatar
kgun kgun is offline
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 4,565
kgun RepRank 3kgun RepRank 3
Default Re: An excellent forum phpBB toolkit.

There are a lot of such lists at various sites.

But I did not know that site, so thank you for the link.
Reply With Quote
  #10 (permalink)  
Old 12-25-2007, 04:03 AM
rose77mary77 rose77mary77 is offline
WebProWorld Member
 

Join Date: Dec 2007
Posts: 27
rose77mary77 RepRank 0
Default Re: An excellent forum phpBB toolkit.

I cant find any new version of toolkit, i am already having oldversion toolkit, i downloasded it from internet, but it not worked.......................
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: excellent, forum, phpbb, toolkit



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
New to making PhpBB Forum Sites Mac 5 Marketing Strategies Discussion Forum 1 05-22-2006 06:32 PM
mkportal error which intregated with phpbb forum bobkom Web Programming Discussion Forum 0 03-24-2006 05:52 AM
PhpBB forum getting error while restoring DB bobkom Web Programming Discussion Forum 3 03-23-2006 05:17 PM
More on the new phpBB forum worm WPW_Feedbot IT Discussion Forum 0 12-21-2004 12:01 PM
Excellent Forum! StephenR. Introductions 1 09-16-2004 11:35 AM


Search Engine Friendly URLs by vBSEO 3.0.0