<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div apple-content-edited="true"><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br class="Apple-interchange-newline"></div></div></span></span></div><div><div>On Mar 5, 2013, at 5:35 PM, "Bryan E. Wooten" &lt;<a href="mailto:bryan.wooten@utah.edu">bryan.wooten@utah.edu</a>&gt;</div><div>&nbsp;wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">

<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; font-size: 14px; font-family: Calibri, sans-serif; ">
<div>
<div>All,</div>
<div><br>
</div>
<div>Last week we had an internal State security audit.</div>
<div><br>
</div>
<div>One of their tests was to copy our CAS login page and host it on their own server We use CAS for our Shib authentication. They then sent an email to many on campus with a link asking them to verify some information, which started with a CAS login page.
 Even though Outlook marked the email a potential phishing some people clicked the link and had their password captured. Sigh.</div>
<div><br>
</div>
<div>We all noticed that the address bar url was suspect. I was thinking I could put some obfusticated &nbsp;java script in the login page and have it email my group in the event someone else tried this. The javascript would detect the incorrect address in the address
 bar. Is this feasible? Or is it too easily disabled?</div></div></div></blockquote><div><br></div><div>How would you get the JS to send you email? &nbsp;I can see maybe trying to make it hit a silent-alarm URL on a server you control. &nbsp;Having just chatted today with our security folks about phished login screens, the one thing they all agreed upon is phishers are lazy. &nbsp;It couldn't hurt to try as long as you go into it knowing that all you're gonna get is the bottom feeders. &nbsp;Anybody with half a clue will see what you're doing there &amp; disable it.</div><div><br></div><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; font-size: 14px; font-family: Calibri, sans-serif; "><div>

<div>One of my co-workers also caught the bogus CAS page, fired up jmeter and hit the bogus login page with 20,000 login attempts. That brought the bogus login web server down. Got to love DDOS. The auditors said that was unethical. Hehe.</div></div></div></blockquote><div><br></div><div>unethical? &nbsp;Hey, you pull a knife &amp; I'm pulling a gun. :-)</div><div><br></div></div><div><span class="Apple-style-span" style="border-collapse: separate; border-spacing: 0px; "><span class="Apple-style-span" style="border-collapse: separate; border-spacing: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div>--</div><div>David Langenberg</div><div>Identity &amp; Access Management</div><div>The University of Chicago</div><div><br></div></div></span><br class="Apple-interchange-newline"></span><br class="Apple-interchange-newline"></div></body></html>