Silly Spammer...
Tuesday, April 03, 2007
Looks like someone needs to work on their l33t h4x0r skills...I received a spam e-mail to a class listserve with a link to a PNG file hosted at ImageShack. Assuming it to be malicious (as it probably is/was), I WGET'ed it, CURLed it, and did my best to try and get it, even Sandboxing my browser and just visiting the link with NoScript denying globally (yes, I was that frustrated). Then I looked at the link:
hxxp://[REMOVED]imageshack.us/my.php?image=w7xp5.png
The guy didn't send the web address -- he spammed the link from his own logged-in session on the site. Meaning, sans cookie or hidden fields in the site's HTML, there's no session data, nothing to point to his file uniquely, and just a redirect to the main page. Oops.
(And I was all excited to dissect some malware, too...)
- David
Labels: sheer stupidity, spam
posted by David @ 11:39 AM,