Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

New Tool Automates Spam

Cheap software promises to post 1,100 messages to Web forums in less than 15 minutes

Just when you thought you had that spam under control: There's a new, inexpensive software package out that helps spammers send out their messages -- and frequently, malware -- at record speeds.

Security researchers at Panda Labs yesterday reported that they have spotted the sale of a new tool called XRumer that promises to help spammers get their messages out to larger numbers of users in less time than ever before.

XRumer, which retails for $450, automates the process of registering, logging onto and posting messages on online forums and Websites that accept comments. The software could help a spammer post a message to myriad online communities, including blogs, wikis, or guestbooks. It is capable of responding to many types of "captcha" images that are designed to prevent automated postings, according to Botmaster, which sells the program.

XRumer works with another Botmaster application, Hrefer, a $50 tool that seeks out forums and other Web pages where public comments are accepted. Hrefer finds the pages that can accept the spam messages, and XRumer handles the registration and posting of those messages, Botmaster says. Working together, the tools also give spammers a list of proxies that they can use to hide their originating IP addresses.

Although Panda Labs is reporting XRumer as a security threat, Botmaster's Website contends that the software breaks no laws.

"In no way does XRumer act like a spam-bot," Botmaster says. "Spam is defined in legislation as unsolicited email, whereas XRumer simply posts messages created by users, which cannot be illegal, providing the user does not [post] anything prohibited by the law." Most anti-spam laws only apply to messages sent to users' email boxes, not to public forums where users read and submit messages voluntarily, Botmaster maintains.

Forum moderators and Webmasters can usually remove spam messages, but XRumer is set up to avoid automated systems that filter "offtopic" messages, Botmaster says.

Panda Labs warns enterprises that online comment pages and forums are becoming increasingly popular targets. "It has become more and more usual to see Websites -- forums, blogs, wikis, guestbooks, etc. -- that contain advertising comments or links that direct users to sites that infect their systems with malware," the security vendor says.

— Tim Wilson, Site Editor, Dark Reading

  • Panda Software Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
    Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
    6 Top Nontechnical Degrees for Cybersecurity
    Curtis Franklin Jr., Senior Editor at Dark Reading,  11/21/2019
    DevSecOps: The Answer to the Cloud Security Skills Gap
    Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    Navigating the Deluge of Security Data
    In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-13157
    PUBLISHED: 2019-11-22
    nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
    CVE-2012-2079
    PUBLISHED: 2019-11-22
    A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
    CVE-2019-11325
    PUBLISHED: 2019-11-21
    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
    CVE-2019-18887
    PUBLISHED: 2019-11-21
    An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
    CVE-2019-18888
    PUBLISHED: 2019-11-21
    An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. T...