<div dir="ltr">Well, there was a little more to it than the DoS to us turning it off, but we did all start laughing when we saw them rolling in.  I think your internal Security Officers were worried about the liability of your institution for attempting to take down a machine that doesn&#39;t belong to you.  Did he tell you what he was putting in the Username and Password strings?  You should ask him sometime.<br>

<br>I&#39;m under NDA, but we walked out of your datacenter with more than just a laptop.  Your new datacenter you&#39;re moving to made us all jealous though.<br><br>It was good times at the U, and you guys took it in the right spirit - acknowledge your weaknesses and set goals for improvement.  And it&#39;s always better to find out from a friend than from someone else.<div>

<br></div><div style>Cheers,</div><div style><br></div><div style>Chuck</div><div style>USHE Security Auditor</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Mar 5, 2013 at 5:35 PM, Bryan E. Wooten <span dir="ltr">&lt;<a href="mailto:bryan.wooten@utah.edu" target="_blank">bryan.wooten@utah.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div style="font-size:14px;font-family:Calibri,sans-serif;word-wrap:break-word">
<div>
<div>All,</div>
<div><br>
</div>
<div>Last week we had an internal State security audit.</div>
<div><br>
</div>
<div>One of their tests was to copy our CAS login page and host it on their own server We use CAS for our Shib authentication. They then sent an email to many on campus with a link asking them to verify some information, which started with a CAS login page.
 Even though Outlook marked the email a potential phishing some people clicked the link and had their password captured. Sigh.</div>
<div><br>
</div>
<div>We all noticed that the address bar url was suspect. I was thinking I could put some obfusticated  java script in the login page and have it email my group in the event someone else tried this. The javascript would detect the incorrect address in the address
 bar. Is this feasible? Or is it too easily disabled?</div>
<div><br>
</div>
<div>One of my co-workers also caught the bogus CAS page, fired up jmeter and hit the bogus login page with 20,000 login attempts. That brought the bogus login web server down. Got to love DDOS. The auditors said that was unethical. Hehe.</div>


<div> </div>
<div>Also, not CAS related, they also soaked some paper in hot water and slide it under a door. This triggered the inside infrared detector and unlocked the door from the inside, allowing access a computer room. There they found a laptop that was not locked
 and used the information on the laptop to social engineer password resets with help desk. Evil.</div>
<div><br>
</div>
<div>Know the enemy.</div>
<div><br>
</div>
<div>Cheers,</div>
<div><br>
</div>
<div>Bryan</div>
</div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>