PHPBB forum spam bots can create username, bypass captcha and post their topic

 

Phpbb is a free online forum available and thousands love using it in different ways for exchange of ideas, discussions or build a business. However the spammers are equally busy running auto bots which can create users , fill up captcha and post their own spam topic.

In a recent research at mobilesecurityresearch, we observed that  it took approximately three weeks before 24 bot users signed up and posted topics on forums. This forum was not advertised to attract traffic.

Below is the screenshot of the forum we observed and the users with post.  Its almost impossible to believe that these are bots.

PHPBB_mobilesecuritythreat_post

 

This also shows  that we can never assume that our site will never be visited by anyone if its not marketed. Online spiders, bots keep checking all kinds of urls like how Google or bing bot works. The only difference are their intentions after collecting data and how they use it.

Share Button

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>