<div dir="ltr">A phish, let alone a spear phish, will always be any institution&#39;s weakest spot.  Not speaking about the Univ of Utah directly, but in general, what Jim is saying is exactly right.  It&#39;s the reason any good con works well.  The more routine it feels, the more likely it is to fool someone.  Again not speaking directly to what happened at UofU, but in general terms, as we do Phishing Tests, we usually leave a sprinkling of clues in them: bad certs, IP&#39;s instead any kind of name that can be resolved etc.  Despite all of that we find most people who fall for it have done exactly what Jim&#39;s closing remarks have said.  Nobody notices the address bar details and warning signs.<div class="gmail_extra">

<br></div><div class="gmail_extra">As we audit our State Institutions, a phish falls into Control #9, of the SANS Top 20 Critical Controls, for us.  <a href="http://www.sans.org/critical-security-controls/">http://www.sans.org/critical-security-controls/</a>  It seems cheesy to teach about phishing, to most IT people, but we can prove time and time again that it&#39;s necessary and that even IT people can and will fall for it - let alone the general public of the institution.</div>

<div class="gmail_extra"><br></div><div class="gmail_extra">FWIW,</div><div class="gmail_extra"><br></div><div class="gmail_extra">Chuck<br><br><div class="gmail_quote">On Tue, Mar 5, 2013 at 8:43 PM, Jim Fox <span dir="ltr">&lt;<a href="mailto:fox@washington.edu" target="_blank">fox@washington.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><br>
<br>
Some years ago I was testing an upgrade to our weblogin service.  For that I used a login page that resembled our real login page, but contained, in big red letters, &quot;This is a test! Do not enter your real password!&quot;<br>


<br>
Nonetheless, more than a third of users hitting that page did enter their real ids and passwords.  These were IT people.<br>
<br>
We tend to see patterns, not detail.  You access, say, a groups service and you get a page that looks like the groups service.  Nobody looks at the URL.  That kind of detail would use up your whole day.  If, in the interim, you are redirected to login, that&#39;s common, happens every morning.  You enter the information and move on---without thought.    Like when you get on the city bus in the morning.  You don&#39;t ask to see the driver&#39;s license, the vehicle&#39;s  registration.  It looks like a bus; you get on.<br>


<br>
I suspect &quot;you all&quot; did not notice the address bar was suspect.<br>
<span class=""><font color="#888888"><br>
Jim<br>
</font></span><div class=""><div class="h5"><br>
<br>
<br>
On Mar 5, 2013, at 4:35 PM, Bryan E. Wooten wrote:<br>
<br>
&gt; All,<br>
&gt;<br>
&gt; Last week we had an internal State security audit.<br>
&gt;<br>
&gt; One of their tests was to copy our CAS login page and host it on their own server We use CAS for our Shib authentication. They then sent an email to many on campus with a link asking them to verify some information, which started with a CAS login page. Even though Outlook marked the email a potential phishing some people clicked the link and had their password captured. Sigh.<br>


&gt;<br>
&gt; We all noticed that the address bar url was suspect. I was thinking I could put some obfusticated  java script in the login page and have it email my group in the event someone else tried this. The javascript would detect the incorrect address in the address bar. Is this feasible? Or is it too easily disabled?<br>


&gt;<br>
&gt; One of my co-workers also caught the bogus CAS page, fired up jmeter and hit the bogus login page with 20,000 login attempts. That brought the bogus login web server down. Got to love DDOS. The auditors said that was unethical. Hehe.<br>


&gt;<br>
&gt; Also, not CAS related, they also soaked some paper in hot water and slide it under a door. This triggered the inside infrared detector and unlocked the door from the inside, allowing access a computer room. There they found a laptop that was not locked and used the information on the laptop to social engineer password resets with help desk. Evil.<br>


&gt;<br>
&gt; Know the enemy.<br>
&gt;<br>
&gt; Cheers,<br>
&gt;<br>
&gt; Bryan<br>
</div></div><div class=""><div class="h5">&gt; --<br>
&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div>