[Full-Disclosure] Suspect phpBB users

Ron Brogden domains at islandnet.com
Wed Dec 29 18:58:40 GMT 2004


On December 25, 2004 15:54, Jack Yan wrote:
>     We have since upgraded, but among our new users over the last few days 
> have been a Weber361, a Weber395, and a nderevyanko.

This looks like the fallout from a standard run of the mill spam bot.  The 
point of its actions being to generate as many distinct links back to the 
user's site as possible so as to increase their search engine placement.  
This is similar to referrer spamming in HTTP logs - just in this case it is 
an automated bot spamming forums instead of some other target.  I doubt it is 
caused by a worm, more likely one or more machines running dedicated software 
(though it is possible this is installed on zombie machines I suppose).

Cheers




Full-Disclosure is hosted and sponsored by Secunia.