<div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Dec 18, 2012 at 8:10 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">Seriously, we just got phished in this way (phisher cloned our IdP page<br>
&gt;and once you entered creds would POST them to the IdP. As a response we<br>
&gt;ended up modifying error.jsp to say something like, &quot;Does this email look<br>
&gt;familiar &lt;img src=&quot;phishMsg.png&quot; /&gt;?<br>
&gt;  If so, call IT Security&quot;.<br>
<br>
</div>David, can you file a RFE so I remember to add a nonce of some sort to the<br>
default page? I can&#39;t rely on a key like my custom handler can, but we<br>
have the login context to use, so I can do something based on that.</blockquote></div><br>SIDP-568</div><div class="gmail_extra"><br></div><div class="gmail_extra">Thanks Scott</div><div class="gmail_extra"><br>Dave<br clear="all">
<div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div><br>
</div>