Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

New Tool Automates Spam

Cheap software promises to post 1,100 messages to Web forums in less than 15 minutes

Just when you thought you had that spam under control: There's a new, inexpensive software package out that helps spammers send out their messages -- and frequently, malware -- at record speeds.

Security researchers at Panda Labs yesterday reported that they have spotted the sale of a new tool called XRumer that promises to help spammers get their messages out to larger numbers of users in less time than ever before.

XRumer, which retails for $450, automates the process of registering, logging onto and posting messages on online forums and Websites that accept comments. The software could help a spammer post a message to myriad online communities, including blogs, wikis, or guestbooks. It is capable of responding to many types of "captcha" images that are designed to prevent automated postings, according to Botmaster, which sells the program.

XRumer works with another Botmaster application, Hrefer, a $50 tool that seeks out forums and other Web pages where public comments are accepted. Hrefer finds the pages that can accept the spam messages, and XRumer handles the registration and posting of those messages, Botmaster says. Working together, the tools also give spammers a list of proxies that they can use to hide their originating IP addresses.

Although Panda Labs is reporting XRumer as a security threat, Botmaster's Website contends that the software breaks no laws.

"In no way does XRumer act like a spam-bot," Botmaster says. "Spam is defined in legislation as unsolicited email, whereas XRumer simply posts messages created by users, which cannot be illegal, providing the user does not [post] anything prohibited by the law." Most anti-spam laws only apply to messages sent to users' email boxes, not to public forums where users read and submit messages voluntarily, Botmaster maintains.

Forum moderators and Webmasters can usually remove spam messages, but XRumer is set up to avoid automated systems that filter "offtopic" messages, Botmaster says.

Panda Labs warns enterprises that online comment pages and forums are becoming increasingly popular targets. "It has become more and more usual to see Websites -- forums, blogs, wikis, guestbooks, etc. -- that contain advertising comments or links that direct users to sites that infect their systems with malware," the security vendor says.

— Tim Wilson, Site Editor, Dark Reading

  • Panda Software Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    News
    A Startup With NSA Roots Wants Silently Disarming Cyberattacks on the Wire to Become the Norm
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/11/2021
    Edge-DRsplash-10-edge-articles
    Cybersecurity: What Is Truly Essential?
    Joshua Goldfarb, Director of Product Management at F5,  5/12/2021
    Commentary
    3 Cybersecurity Myths to Bust
    Etay Maor, Sr. Director Security Strategy at Cato Networks,  5/11/2021
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win an Amazon Gift Card! Click Here
    Latest Comment: Google Maps is taking "interactive" to a whole new level!
    Current Issue
    2021 Top Enterprise IT Trends
    We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
    Flash Poll
    How Enterprises are Developing Secure Applications
    How Enterprises are Developing Secure Applications
    Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-21830
    PUBLISHED: 2021-05-17
    A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
    CVE-2020-21832
    PUBLISHED: 2021-05-17
    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.
    CVE-2020-21833
    PUBLISHED: 2021-05-17
    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.
    CVE-2020-21834
    PUBLISHED: 2021-05-17
    A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.
    CVE-2020-21835
    PUBLISHED: 2021-05-17
    A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.