Waraxe IT Security Portal
Login or Register
March 10, 2025
Members List
IRC chat
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
Sql Char Encoder
y3dips ITsec
Md5 Cracker
User Manuals
Recommend Us
Your Account
User Info
Welcome, Anonymous

Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 59
Members: 0
Total: 59
Full disclosure
SEC Consult SA-20250226-0 :: Multiple vulnerabilities in Siemens A8000 CP-8050 & CP-8031 PLC
Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Self Stored XSS - acp2sev7.2.2
Python's official documentation contains textbook example of insecure code (XSS)
Re: Netgear Router Administrative Web Interface Lacks Transport Encryption By Default
Monero 18.3.4 zero-day DoS vulnerability has been droppedpublicly on social network.
Netgear Router Administrative Web Interface Lacks Transport Encryption By Default
[CVE-2024-54756] GZDoom <= 4.13.1 Arbitrary Code Execution viaMalicious ZScript
Re: Text injection on https://www.google.com/so rry/index via ?q parameter (no XSS)
SEC Consult SA-20250211-0 :: Multiple vulnerabilities in Wattsense Bridge
APPLE-SA-02-10-2025-2 iPadOS 17.7.5
APPLE-SA-02-10-2025-1 iOS 18.3.1 and iPadOS 18.3.1
CVE-2024-55447: Access Control in Paxton Net2 software (update)
ChatGPT AI finds "security concern" (XSS) in DeepSeek's code
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> PhpNuke -> Who is JackFromWales4u2?
Post new topicReply to topic View previous topic :: View next topic
Who is JackFromWales4u2?
PostPosted: Sun Sep 05, 2004 3:25 am Reply with quote
Joined: Sep 05, 2004
Posts: 4

I had a random user JackFromWales4u2 register on one of my phpnuke sites. At first I was annoyed at the random registration, but then paranoia took hold. I checked the logs for any obvious or glaring exploits, but I did not see anything.

I then checked the various phpnuke security sites. I was surprised to see that JackFromWales4u2 was also the latest signup at a forum moderator's site.

I then ran a google search on JackFromWales4u2, and google returned 18600 Shocked hits!

From a random check of the various google hits, it seems that JackFromWales4u2 has been very busy with a great number of registrations at these various phpnuke and phpbb sites within a span of a couple of days -- September 1-2, 2004.

Now this screams of an exploit/vulnerability! Is there a script or exploit/vulnerability that is out in the wild that is yet unpatched?

Or am I just being paranoid here?
p.s. you might want to check your own phpnuke sites to see if you've had a visit from JackFromWales4u2, too.
View user's profile Send private message
PostPosted: Sun Sep 05, 2004 3:10 pm Reply with quote
Advanced user
Advanced user
Joined: May 18, 2004
Posts: 181
Location: Serbia

oprime2001 >>> 1,470 results Laughing
I dont think that that is bot,because every member must click on activation link (in mail)..Try contact him,maybe he is just a computer freak Laughing Laughing


We would change the world, but God won't give us the sourcecode...
....Watch the master. Follow the master. Be the master....
View user's profile Send private message
PostPosted: Sun Sep 05, 2004 8:25 pm Reply with quote
Joined: Sep 05, 2004
Posts: 4

But if you take a look at the google hits for oprime2001, most of the hits are on a couple of English sites -- mostly NukeCops, ravenphpscripts and a couple of other phpnuke-related sites.

In contrast, the google search for JackFromWales4u2 returns (now) 24,400 hits over numerous (hundreds? thousands?) different sites using various different languages on all kinds of topics. Furthermore, most of the google results are for registration/profile info -- not regular postings.

What is more disconcerting is what you brought up -- that
every member must click on activation link (in mail)
yet most of the JackFromWales4u2 php-nuke memberships seem to have been registered and activated within a very short period of time (september 1-2, 2004). How?

I could just be too paranoid having websites previously defaced, but things seem fishy. Why the mass registrations on different website topics of different languages within a short period of time? Question
View user's profile Send private message
add user with POST method
PostPosted: Mon Sep 06, 2004 8:26 am Reply with quote
Regular user
Regular user
Joined: Jun 14, 2004
Posts: 16
Location: dunia fana

see :


the POST method more nice to check the HTTP respons of the target.

the GET method more difficult to parsing the HTTP respons.

so someone now can write a little script to add user admin to the phpnuke
with more powerfull parsing of target's HTTP respons !!!

View user's profile Send private message Visit poster's website
PostPosted: Mon Sep 06, 2004 10:37 am Reply with quote
Advanced user
Advanced user
Joined: May 18, 2004
Posts: 181
Location: Serbia

Thats exploits can only add or del admin account..
We are talking about user account..


We would change the world, but God won't give us the sourcecode...
....Watch the master. Follow the master. Be the master....
View user's profile Send private message
add user admin
PostPosted: Mon Sep 06, 2004 10:58 am Reply with quote
Regular user
Regular user
Joined: Jun 14, 2004
Posts: 16
Location: dunia fana

SteX wrote:
Thats exploits can only add or del admin account..
We are talking about user account..

plz read carefully, do u ???

View user's profile Send private message Visit poster's website
PostPosted: Mon Sep 06, 2004 8:25 pm Reply with quote
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu

What can i say, is:

1. PhpBB and PhpNuke registration is complete (activated) after
activation email reply. It's not hard to write script or program, which
first does google search for nuke and phpbb, then registers at all the
sites, next logs in to pop3/imap account and retrieves all the emails,
then parses them and finally activates all the accounts.
Only problem i see, is that "turing number" stuff, which is meant to
protect against automated clients (bots). If that image is not enough
"fuzzy" (like in the case of the most nuke installations), then OCR
software can be used and then nothing can stop automated registrations.

2. What's the goal for doing such "spamming"? One reason can be
"googlespam" for trying to elevate some website's pagerank.
But as far as i know, google is allready aware of such attempts and
this kind of "links" does not count for pagerank.
View user's profile Send private message Send e-mail Visit poster's website
Re: Who is JackFromWales4u2?
PostPosted: Thu Sep 09, 2004 8:59 am Reply with quote
Active user
Active user
Joined: Jul 22, 2004
Posts: 25

oprime2001 wrote:
I then ran a google search on JackFromWales4u2, and google returned 18600 Shocked

Now the sites are 44300 Shocked
View user's profile Send private message
JackFromWales4u2 == spammer >> persona non grata
PostPosted: Thu Sep 09, 2004 1:34 pm Reply with quote
Joined: Sep 05, 2004
Posts: 4

waraxe wrote:
What can i say, is:
2. What's the goal for doing such "spamming"? One reason can be
"googlespam" for trying to elevate some website's pagerank.
But as far as i know, google is allready aware of such attempts and
this kind of "links" does not count for pagerank.

It seems that waraxe was on to something with the above comments. I posted the original post in the security forum at NukeCops. A couple of users there are now reporting that the JackFromWales4u2 account is being used to spam news articles on phpnuke websites with comments with a link to (presumably, their) website.

However, what is more disconcerting is that these users are reporting that ALL of their articles/news were spammed! Again, if that doesn't smell of a script/bot, I don't know what does. I don't see a legitimate reason to keep this JackFromWales4u2 account on your site! Evil or Very Mad
View user's profile Send private message
Who is JackFromWales4u2?
www.waraxe.us Forum Index -> PhpNuke
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic

Powered by phpBB © 2001-2008 phpBB Group

Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.046 Seconds