The Register® — Biting the hand that feeds IT

Feeds

VXers publish blog poisoning tool

Script kiddie tool foils captchas

Agentless Backup is Not a Myth

Virus writers have created a malicious tool capable of automating the publication of spam and links to sites hosting malware on forums and blogs.

XRumer dumbs down the process of posting so-called blog spam. Blog spam has been used as a tactic by penis pill purveyors and others to attract attention and (occasionally) boost search engine rankings. Virus writers picked up the tactic to encourage more punters to visit sites hosting malware.

Up to now the approach has required a modicum of programming skills. The arrival of Xrumer dumbs down the process.

Now even the most clueless newbie can spamvertise their wares for around $450 via various underground forums and websites. According to its creator, XRumer can post over 1,100 comments in less than 15 minutes.

Blogs and forums often contain security measures such as captcha (number and letter codes used to check registration is carried out by a person), or blocking of suspicious IP addresses to avoid automatic registration via robots. XRumer, however, is designed to bypass such security measures. It can recognise text included in several image types, and it contains a long list of computers whose IP address can be used as proxies.

Cyber-crooks first need to specify the message and link they want XRumer to post on different forums, as well as the (false) user name and email address to use in these postings. Then they need to search the net for blogs or forums that allow visitors to add their comments. Miscreants usually use Hrefer (a tool costing around $50) to automate this process.

XRumer can publish comments on sites created by phpBB, PHP-Nuke (with some modification), yaBB, VBulletin, Invision Power Board, IconBoard, UltimateBB, exBB, and phorum.org. Usually, the spam message contains a link to pages infected with malware, although the tool can also be used to advertise websites through spam.

"The success of blogs, forums, etc, has not gone unnoticed to cyber crooks, who use them to try to infect as many people as possible," said Luis Corrons, technical director of PandaLabs. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments
Anonymous Coward

Now *that's* service

"it contains a long list of computers whose IP address can be used as proxies"

So the thingy comes with the seeds of a new blacklist. How nice of them to include that. Of course it's sad that users of the proxies can no longer access any blogs, but then I always thought anonymous browsing was meant to protect against Big Brother, not to sell V!4gr4 etc...

0
0

End of captchas

I'd be delighted to see captchas permanently cracked. The problem is that, although machines can sometimes read them, human beings usually can't!

So, if this particular security device is broken, I shan't miss it.

0
0

V1agra is g8

Pls note th1s 1s NOT a spam message said the woman in the corner, queitly pianting cheese and ham gardn.s

V1agra $200 from a farmacy.....

Sorry couldn't resist tempation....

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?