Don't accept sub domains.
On my traffic script I get these submitted to me almost daily. I know what they are as soon as I see the sub domain url. Most of the time I just hit ban but sometimes I'll let to load to see what is there and always they download something to my desktop called exploit. (I'm on a Mac so they don't affect me)
Like this page
http://funk.lesbi-dream.com
It downloads something to my desktop called 2DimensionOfExploitsEnc.php
|