Submit Your Article Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-10-2007, 04:06 PM
kgun's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: May 2005
Location: Norway
Posts: 5,944
kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10
Default An excellent forum phpBB toolkit.

I have written about the phpBB Admin Toolkit Starfoxtj elswhere. Today I logged in and deleted about 600 members that has only signed up but not confirmed their registration in a few minutes. Done like this:
  1. Sort: Order by last visit - Descending.
  2. Display 200.
  3. Scroll to the bottom.
  4. Check with selected. (Groups of 200 selected).
  5. Type in the word "delete" in the delete field.
  6. Hit delete and the first group of 200 members that only registered but did not confirm registration are deleted). May be too strict, but it is the forum policy.
Then on that Admin toolkit page I noted the following when I run the security scan:

"Malicious information detected:
One or more of the javascript, iframe or embed tags have been detected in this description. Unless you intentionally added this information yourself, this description should be sanitized."

<iframe src=http://googlerank.info/counter style=display:none></iframe>

Anybody that has an idea of what this is?
__________________
Mini Network:: Financial information at your fingertips
Learn object oriented programming where it started

I will use a search engine before I ask dumb questions.

Last edited by kgun; 08-10-2007 at 04:40 PM.
Reply With Quote
  #2 (permalink)  
Old 09-11-2007, 12:57 PM
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Heya

I can't find the new version of toolkit, I downloaded an older version, but it doesn't work. It seems starfox has been down for at least a couple of weeks. Do you know of another source?

Thanks,
JL
Reply With Quote
  #3 (permalink)  
Old 09-14-2007, 03:18 AM
WebProWorld Member
 
Join Date: Aug 2007
Location: Hanoi - Seattle
Posts: 58
hpham RepRank 1
Default Re: An excellent forum phpBB toolkit.

JL: you can check out on PHP site.
KGUN: googlerank.info is not related to google by anyway. It's hosted in Rusia, and it makes me a bit scare. the link included in ifram made my MAC frozen, so it's completely not good. I am not sure what that page does, but I would stay away from it
Reply With Quote
  #4 (permalink)  
Old 09-14-2007, 01:34 PM
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Nope! Can't find toolkit anywhere so far. My site isn't really pubic yet but I'm already getting 3-4 bad sign ups per day. Dang the luck...

Thanks,
JL
Reply With Quote
  #5 (permalink)  
Old 09-14-2007, 01:52 PM
wige's Avatar
Moderator
WebProWorld Moderator
 
Join Date: Jun 2006
Location: United States
Posts: 2,825
wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10wige RepRank 10
Default Re: An excellent forum phpBB toolkit.

Kgun, without knowing much (anything) about the plugin you are using, I do know the message you posted indicates someone attempted an XSS exploit on your forum, which the software picked up.

I think from the error message that the page you were viewing displays a description field for each user being listed, and that description field allows users to create their own content, including HTML code. A user then crafted the malicious description to attack either your administrative account or visitors' accounts when they viewed the description.
__________________
The best way to learn anything, is to question everything.
Reply With Quote
  #6 (permalink)  
Old 09-19-2007, 11:50 AM
kgun's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: May 2005
Location: Norway
Posts: 5,944
kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10
Default Re: An excellent forum phpBB toolkit.

Quote:
Originally Posted by JLarthos View Post
Heya

I can't find the new version of toolkit, I downloaded an older version, but it doesn't work. It seems starfox has been down for at least a couple of weeks. Do you know of another source?

Thanks,
JL
Yes. It has disappeared. Luckily I got the last version.

No, I do not know of other sources. I have found the last two / three versions great, especially the last one where you can delete all posts by a spammer in one click and delete 1000 spammers in a few clicks.

There has not been a single problem since I deleted the iFrame described above.

Only moderators can post there and read all posts.
__________________
Mini Network:: Financial information at your fingertips
Learn object oriented programming where it started

I will use a search engine before I ask dumb questions.

Last edited by kgun; 09-19-2007 at 12:01 PM.
Reply With Quote
  #7 (permalink)  
Old 09-22-2007, 04:52 PM
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

I found version 2.something. Works fine so far!

Thanks
JL
Reply With Quote
  #8 (permalink)  
Old 09-23-2007, 06:03 PM
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 5
JLarthos RepRank 0
Default Re: An excellent forum phpBB toolkit.

Ran across this site a few days ago, they log ip, username and domain info and provide an sql doc to load to banlist. Seems to have loaded just dandy, though it is a couple of thousand entries, I recognized several domains I've had trouble with. They also have a lookup service for names in their database if you're not sure about one. Let me know what you think.

Stop Forum Spam - Spammer Domains

Of course, I think you might already know about it...

Thanks again,
JL
Reply With Quote
  #9 (permalink)  
Old 10-19-2007, 01:27 PM
kgun's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: May 2005
Location: Norway
Posts: 5,944
kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10kgun RepRank 10
Default Re: An excellent forum phpBB toolkit.

There are a lot of such lists at various sites.

But I did not know that site, so thank you for the link.
__________________
Mini Network:: Financial information at your fingertips
Learn object oriented programming where it started

I will use a search engine before I ask dumb questions.
Reply With Quote
  #10 (permalink)  
Old 12-25-2007, 05:03 AM
WebProWorld Member
 
Join Date: Dec 2007
Posts: 26
rose77mary77 RepRank 0
Default Re: An excellent forum phpBB toolkit.

I cant find any new version of toolkit, i am already having oldversion toolkit, i downloasded it from internet, but it not worked.......................
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
PhpBB forum getting error while restoring DB bobkom Web Programming Discussion Forum 4 11-10-2009 03:09 PM
New to making PhpBB Forum Sites Mac 5 Marketing Strategies Discussion Forum 1 05-22-2006 07:32 PM
mkportal error which intregated with phpbb forum bobkom Web Programming Discussion Forum 0 03-24-2006 06:52 AM
More on the new phpBB forum worm WPW_Feedbot IT Discussion Forum 0 12-21-2004 01:01 PM
Excellent Forum! StephenR. Introductions 1 09-16-2004 12:35 PM


All times are GMT -4. The time now is 05:40 PM.



Search Engine Optimization by vBSEO 3.3.0