We had a State security audit
Bryan E. Wooten
bryan.wooten at utah.edu
Wed Mar 6 09:40:15 EST 2013
Thanks for the reply Chuck!
I am not sure what he used for username/pwd. We use jmeter to stress test our CAS login in a test environment so I imagine he just set the ip to your fake CAS screen. But I'll ask him.
BTW, the laptop you were given was originally assigned to me, but we deleted my account before handing it over to you. I had only used it to test network connectivity in my new office.
Cheers,
Bryan
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Chuck Kimber
Sent: Tuesday, March 05, 2013 8:13 PM
To: Shib Users
Subject: Re: We had a State security audit
Well, there was a little more to it than the DoS to us turning it off, but we did all start laughing when we saw them rolling in. I think your internal Security Officers were worried about the liability of your institution for attempting to take down a machine that doesn't belong to you. Did he tell you what he was putting in the Username and Password strings? You should ask him sometime.
I'm under NDA, but we walked out of your datacenter with more than just a laptop. Your new datacenter you're moving to made us all jealous though.
It was good times at the U, and you guys took it in the right spirit - acknowledge your weaknesses and set goals for improvement. And it's always better to find out from a friend than from someone else.
Cheers,
Chuck
USHE Security Auditor
On Tue, Mar 5, 2013 at 5:35 PM, Bryan E. Wooten <bryan.wooten at utah.edu<mailto:bryan.wooten at utah.edu>> wrote:
All,
Last week we had an internal State security audit.
One of their tests was to copy our CAS login page and host it on their own server We use CAS for our Shib authentication. They then sent an email to many on campus with a link asking them to verify some information, which started with a CAS login page. Even though Outlook marked the email a potential phishing some people clicked the link and had their password captured. Sigh.
We all noticed that the address bar url was suspect. I was thinking I could put some obfusticated java script in the login page and have it email my group in the event someone else tried this. The javascript would detect the incorrect address in the address bar. Is this feasible? Or is it too easily disabled?
One of my co-workers also caught the bogus CAS page, fired up jmeter and hit the bogus login page with 20,000 login attempts. That brought the bogus login web server down. Got to love DDOS. The auditors said that was unethical. Hehe.
Also, not CAS related, they also soaked some paper in hot water and slide it under a door. This triggered the inside infrared detector and unlocked the door from the inside, allowing access a computer room. There they found a laptop that was not locked and used the information on the laptop to social engineer password resets with help desk. Evil.
Know the enemy.
Cheers,
Bryan
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130306/983eb311/attachment-0001.html
More information about the users
mailing list