On Monday, November 8, 2004, 6:45:01 PM, Jim wrote: JM> Has anyone noticed a influx of email messages with spam type JM> content that seems to link to a 1639 port on a remote webserver.� JM> I have had several reports of these in the last half hour, some JM> appear to be fake paypal scams, one was porn related, but both JM> link to the same site and one user actually reported the message JM> causing their PC to reboot.� Any else seen these.
We're going to start looking for this. If we can find a safe general pattern then we will code a rule. Thanks for the heads up. As for the PC rebooting - watch out for image or other html based exploits that might be deployed on this alternate port. If a PC is not completely patched, or if a new exploit has been found (surprize %^b) then this could explain the reboot on a preview. _M This E-Mail came from the Message Sniffer mailing list. For information and (un)subscription instructions go to http://www.sortmonster.com/MessageSniffer/Help/Help.html
