We had a State security audit
Chuck Kimber
chuck.kimber at usu.edu
Tue Mar 5 22:13:10 EST 2013
Well, there was a little more to it than the DoS to us turning it off, but
we did all start laughing when we saw them rolling in. I think your
internal Security Officers were worried about the liability of your
institution for attempting to take down a machine that doesn't belong to
you. Did he tell you what he was putting in the Username and Password
strings? You should ask him sometime.
I'm under NDA, but we walked out of your datacenter with more than just a
laptop. Your new datacenter you're moving to made us all jealous though.
It was good times at the U, and you guys took it in the right spirit -
acknowledge your weaknesses and set goals for improvement. And it's always
better to find out from a friend than from someone else.
Cheers,
Chuck
USHE Security Auditor
On Tue, Mar 5, 2013 at 5:35 PM, Bryan E. Wooten <bryan.wooten at utah.edu>wrote:
> All,
>
> Last week we had an internal State security audit.
>
> One of their tests was to copy our CAS login page and host it on their
> own server We use CAS for our Shib authentication. They then sent an email
> to many on campus with a link asking them to verify some information, which
> started with a CAS login page. Even though Outlook marked the email a
> potential phishing some people clicked the link and had their password
> captured. Sigh.
>
> We all noticed that the address bar url was suspect. I was thinking I
> could put some obfusticated java script in the login page and have it
> email my group in the event someone else tried this. The javascript would
> detect the incorrect address in the address bar. Is this feasible? Or is it
> too easily disabled?
>
> One of my co-workers also caught the bogus CAS page, fired up jmeter and
> hit the bogus login page with 20,000 login attempts. That brought the bogus
> login web server down. Got to love DDOS. The auditors said that was
> unethical. Hehe.
>
> Also, not CAS related, they also soaked some paper in hot water and slide
> it under a door. This triggered the inside infrared detector and unlocked
> the door from the inside, allowing access a computer room. There they found
> a laptop that was not locked and used the information on the laptop to
> social engineer password resets with help desk. Evil.
>
> Know the enemy.
>
> Cheers,
>
> Bryan
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130305/aeacdbc9/attachment.html
More information about the users
mailing list