E. Falk wrote:
Anyone else been seeing a lot of these come in? The text includes a
snippet about the Iran Nuclear situation and a link to a "full article".
The article appears to have been pinched from elsewhere, but the page
includes javascript which appears to use a buffer overflow to load a
.hta file.
All the links end in votnews dot com - thankfully the uribl's kept this
one from hitting my users. Just thought I'd throw out a warning since
it's not just more political spam, there's a payload.
Evan
Found another one from a few days back, this time the news story was
about the 14 Marines killed in Iraq. Same IP address in China, this time
with the url pointing to vbnnews dot com.
Obviously this site is known to the URIBL people... wonder how long it's
been out there.
Evan