Our friends over at WebSense have put together a killer video that shows the VML exploit in action, resulting in a fake Paypal website that steals your login information.

It’s a must see video.   

Now — don’t go off trying to visit the site in question, as you’ll find yourself with a lovely infection.  Just watch the video, which is safe for viewing.

Their blog entry on the movie.

And the movie itself (a takedown effort is in progress on this site).


Alex Eckelberry