We had a State security audit
Chuck Kimber
chuck.kimber at usu.edu
Tue Mar 5 23:10:30 EST 2013
A phish, let alone a spear phish, will always be any institution's weakest
spot. Not speaking about the Univ of Utah directly, but in general, what
Jim is saying is exactly right. It's the reason any good con works well.
The more routine it feels, the more likely it is to fool someone. Again
not speaking directly to what happened at UofU, but in general terms, as we
do Phishing Tests, we usually leave a sprinkling of clues in them: bad
certs, IP's instead any kind of name that can be resolved etc. Despite all
of that we find most people who fall for it have done exactly what Jim's
closing remarks have said. Nobody notices the address bar details and
warning signs.
As we audit our State Institutions, a phish falls into Control #9, of the
SANS Top 20 Critical Controls, for us.
http://www.sans.org/critical-security-controls/ It seems cheesy to teach
about phishing, to most IT people, but we can prove time and time again
that it's necessary and that even IT people can and will fall for it - let
alone the general public of the institution.
FWIW,
Chuck
On Tue, Mar 5, 2013 at 8:43 PM, Jim Fox <fox at washington.edu> wrote:
>
>
> Some years ago I was testing an upgrade to our weblogin service. For that
> I used a login page that resembled our real login page, but contained, in
> big red letters, "This is a test! Do not enter your real password!"
>
> Nonetheless, more than a third of users hitting that page did enter their
> real ids and passwords. These were IT people.
>
> We tend to see patterns, not detail. You access, say, a groups service
> and you get a page that looks like the groups service. Nobody looks at the
> URL. That kind of detail would use up your whole day. If, in the interim,
> you are redirected to login, that's common, happens every morning. You
> enter the information and move on---without thought. Like when you get
> on the city bus in the morning. You don't ask to see the driver's license,
> the vehicle's registration. It looks like a bus; you get on.
>
> I suspect "you all" did not notice the address bar was suspect.
>
> Jim
>
>
>
> On Mar 5, 2013, at 4:35 PM, Bryan E. Wooten wrote:
>
> > All,
> >
> > Last week we had an internal State security audit.
> >
> > One of their tests was to copy our CAS login page and host it on their
> own server We use CAS for our Shib authentication. They then sent an email
> to many on campus with a link asking them to verify some information, which
> started with a CAS login page. Even though Outlook marked the email a
> potential phishing some people clicked the link and had their password
> captured. Sigh.
> >
> > We all noticed that the address bar url was suspect. I was thinking I
> could put some obfusticated java script in the login page and have it
> email my group in the event someone else tried this. The javascript would
> detect the incorrect address in the address bar. Is this feasible? Or is it
> too easily disabled?
> >
> > One of my co-workers also caught the bogus CAS page, fired up jmeter and
> hit the bogus login page with 20,000 login attempts. That brought the bogus
> login web server down. Got to love DDOS. The auditors said that was
> unethical. Hehe.
> >
> > Also, not CAS related, they also soaked some paper in hot water and
> slide it under a door. This triggered the inside infrared detector and
> unlocked the door from the inside, allowing access a computer room. There
> they found a laptop that was not locked and used the information on the
> laptop to social engineer password resets with help desk. Evil.
> >
> > Know the enemy.
> >
> > Cheers,
> >
> > Bryan
> > --
> > To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130305/2d2b3ef0/attachment-0001.html
More information about the users
mailing list