On Monday, November 8, 2004, 6:45:01 PM, Jim wrote:

JM> Has anyone noticed a influx of email messages with  spam type
JM> content that seems to link to a 1639 port on a remote webserver.� 
JM> I have had several reports of these in the last half hour, some
JM> appear to be  fake paypal scams, one was porn related, but both
JM> link to the same site and one  user actually reported the message
JM> causing their PC to reboot.� Any else  seen these.

We're going to start looking for this. If we can find a safe general
pattern then we will code a rule. Thanks for the heads up.

As for the PC rebooting - watch out for image or other html based
exploits that might be deployed on this alternate port. If a PC is not
completely patched, or if a new exploit has been found (surprize %^b)
then this could explain the reboot on a preview.

_M




This E-Mail came from the Message Sniffer mailing list. For information and 
(un)subscription instructions go to 
http://www.sortmonster.com/MessageSniffer/Help/Help.html

Reply via email to