News:

SMF 2.1.4 has been released! Take it for a spin! Read more.

Main Menu

Regular Visits from Kris Barteo ISP

Started by Thunderdownunder, June 02, 2009, 10:24:57 AM

Previous topic - Next topic

Thunderdownunder

My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

babjusi

Quote from: Thunderdownunder on June 02, 2009, 10:24:57 AM
My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

If you have banned that IP, then you got nothing to worry about. Let him/her/it visit all they want.

Aleksi "Lex" Kilpinen

Also, the latest update of SMF should protect you from krisbarteo, and so no real need to worry any more ;)
Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

How you can help SMF

catfished

Quote from: LexArma on June 02, 2009, 10:43:56 AM
Also, the latest update of SMF should protect you from krisbarteo, and so no real need to worry any more ;)

That's true until they come up with a new exploit to get in and do their dirty work. Unfortunately, the game goes on.

I hope it's clear to everyone that I am in no way questioning the skills of the SMF team, they're doing everything possible to keep ahead, it's just that the #$^&$# keep coming up with more exploits.
You use and like this forum software? Then show your appreciation and support by becoming a Charter Member.



CatfishEd.com

DJ Homer

Quote from: Thunderdownunder on June 02, 2009, 10:24:57 AM
My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

Hi there im kinda new to this and dont know who or what ""Kris Barteo"" is

could someone please tell me and is it worth blocking/banning the ip address?

When I was younger I hated going to weddings. it seemed that all of my aunts and the grandmotherly types used to come up to me, poking me in the ribs and cackling, telling me, 'You're next.' They stopped that crap after I started doing the same thing to them at funerls


babjusi

Quote from: back-to-the-past.co.uk on June 02, 2009, 12:47:56 PM
Quote from: Thunderdownunder on June 02, 2009, 10:24:57 AM
My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

Hi there im kinda new to this and dont know who or what ""Kris Barteo"" is

could someone please tell me and is it worth blocking/banning the ip address?

This fella/gal/robot is the cause of the hack of a lot of smf forums lately. If you google that nick or search for it here as well you will have the whole picture pretty soon.

DJ Homer

Quote from: babjusi on June 02, 2009, 12:50:32 PM
Quote from: back-to-the-past.co.uk on June 02, 2009, 12:47:56 PM
Quote from: Thunderdownunder on June 02, 2009, 10:24:57 AM
My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

Hi there im kinda new to this and dont know who or what ""Kris Barteo"" is

could someone please tell me and is it worth blocking/banning the ip address?

This fella/gal/robot is the cause of the hack of a lot of smf forums lately. If you google that nick or search for it here as well you will have the whole picture pretty soon.

so is it worth me banning the IP Address

When I was younger I hated going to weddings. it seemed that all of my aunts and the grandmotherly types used to come up to me, poking me in the ribs and cackling, telling me, 'You're next.' They stopped that crap after I started doing the same thing to them at funerls


babjusi

Quote from: back-to-the-past.co.uk on June 02, 2009, 12:52:15 PM
Quote from: babjusi on June 02, 2009, 12:50:32 PM
Quote from: back-to-the-past.co.uk on June 02, 2009, 12:47:56 PM
Quote from: Thunderdownunder on June 02, 2009, 10:24:57 AM
My apologies if
1) I'm saying something obvious, or
2)  I'm saying it in the wrong place.

As a forum admin, I immediately banned Kris Barteo on May 18 when  I became aware of what it was.

Since the banning, the same ISP has revisited my site (as a guest) on NINE occasions over four different days. The ISP used has been the same on every occasion........ 94.142.129.212.

Hope the above is of assistance to other readers



cheers

Hi there im kinda new to this and dont know who or what ""Kris Barteo"" is

could someone please tell me and is it worth blocking/banning the ip address?

This fella/gal/robot is the cause of the hack of a lot of smf forums lately. If you google that nick or search for it here as well you will have the whole picture pretty soon.

so is it worth me banning the IP Address

One would think so.

perplexed

Please see the following topic for more info http://www.simplemachines.org/community/index.php?topic=313201.0

As a new member, one of the best things you can do is get into the habit of searching the forum before posting as there is plenty of information readily available on this character.  It is definitely worth blocking the IP address but please read the related topics.

lol  Warning - while you were typing 3 new replies have been posted. You may wish to review your post.                            

DJ Homer

ok thank you.

do you think there are any other IP addresses you think i should ban

When I was younger I hated going to weddings. it seemed that all of my aunts and the grandmotherly types used to come up to me, poking me in the ribs and cackling, telling me, 'You're next.' They stopped that crap after I started doing the same thing to them at funerls



DJ Homer

i have just downloaded that kb_scan.php and i have changed cmode settings to 777 and im getting the following error

QuoteNotice: Undefined index: no_view_links in /home/backtoth/public_html/tester/Sources/Subs.php on line 1310

Notice: Undefined index: no_view_links in /home/backtoth/public_html/tester/Sources/Subs.php on line 1316

Notice: Undefined index: no_view_links in /home/backtoth/public_html/tester/Sources/Subs.php on line 1572

Notice: Undefined index: no_view_links in /home/backtoth/public_html/tester/Sources/Subs.php on line 1578
Admin privileges required.

any ideas

When I was younger I hated going to weddings. it seemed that all of my aunts and the grandmotherly types used to come up to me, poking me in the ribs and cackling, telling me, 'You're next.' They stopped that crap after I started doing the same thing to them at funerls


weisus

I too have been hit by krisbarteo; the IP that was used on my forums is: 94.142.129.147. Perhaps someone can help me with an issue that I seem to be having as a result of this attack. The only glitch that I have noticed so far is...when you login or logoff, on the first try you receive a blank page. Then if you use the browser back button and retry, success. I have banned the user and all related profile info and deleted the 1x1 attachment. I have also uploaded the scan tool to my root directory and it came back clean, green for all of the php files in my db...does anyone know why I would still be having problems? I am running 1.1.8 on one forum and 1.1.5 on another. If I upgrade both to 1.1.9, would I have to manually clean all of the files first, or would the upgrade take care of that? Any help would be appreciated.

Thenewguy2009

just to to admin cp -> members -> ban-> and then ban that ip from the forum.  The steps are there.  you have two address that hes expolited from so put both in. 

That ip is coming from estonia

weisus

As I said in my post, I have already taken those steps, but I still have the symptoms as mentioned. If anyone has any thoughts, they would be greatly appreciated.

Advertisement: