On Fri, Oct 05, 2007 at 04:24:39PM -0500, Arthur Pemberton wrote: > > machines. "The vast majority of [the phishing sites] we saw were on > > rootkit-ed Linux boxes, which was rather startling. We expected a > > http://tinyurl.com/36nfsm > How do they know that the attacks are from rooted linux boxes? Because it's generally pretty easy to tell the operating system a given web site is running on. Note that they're talking about *phishing sites*, not the sites from which phishing spam or whatever originates. -- Matthew Miller mattdm@xxxxxxxxxx <http://mattdm.org/> Boston University Linux ------> <http://linux.bu.edu/>