|
On the non-phpsuexec servers, the amount of phish uploads is important because this also means that other scammers were able to upload files to mass send mail (most commonly and not very imaginatively named mailer.php) so that is why the email source column is also high.
On the phpsuexec servers the ability to upload files into random 777 directories is completely reduced. Random spam sent on those (419, phish, etc) happens only because of a certain type of mail script used by the account holder.
If you have any questions about these results please reply here and let me know. I'd be very happy to go into this deeper.
|