CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Spear phishing attack in progress - U.S. universities

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4845
Location: USA

PostPosted: Fri Feb 01, 2008 8:41 am    Post subject: Spear phishing attack in progress - U.S. universities
Reply with quote

FYI...

- http://isc.sans.org/diary.html?storyid=3917
Last Updated: 2008-02-01 03:58:06 UTC - "We’ve had a few reports of Universities/Colleges being hit with some very targeted emails trying to get the userid and password of students. The email is usually along these lines:

Subject VERIFY YOUR xxxxxx EMAIL ACCOUNT NOW

Dear xxxxx Email Account Owner,

This message is from xxxxx messaging center to all xxxxx email account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused xxxxx email account to create more space for new accounts.
To prevent your account from closing you will have to update it below so that we will know that it's a present used account.
CONFIRM YOUR EMAIL IDENTITY BELOW
Email Username : .......... .....
EMAIL Password : ................
Date of Birth : .................
Country or Territory : ..........
Warning!!! Account owner that refuses to update his or her account within Seven days of receiving this warning will lose his or her account permanently.
Thank you for using xxxxxx!
Warning Code:VX2G99AAJ

Thanks,

Xxxxx Team

The sender will be often be xxxxxteam @ isp used to send msg or uni address. The reply address will be external to the organization. In the sample we have it is usxxxxxxcountupgrade @ live.com. (where xxxxx is the domain name used by the institution, without the .edu). The message often passes through some SPAM filters due to the relatively low volume of messages. If you have some samples we’d be interested in a copy. Look for messages to multiple recipients and increased volume of internal email to one specific external address... educate your students."

Shocked


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Fri Feb 01, 2008 8:51 am    Post subject:
Reply with quote

This article on Spear Phishing needs to go on the Front Page at CCSP.


_________________
I wish you all the best and nothing less.
Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3013

Forums Admin MVP Premium Team F@H

PostPosted: Fri Feb 01, 2008 5:35 pm    Post subject:
Reply with quote

DONE!


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Fri Feb 01, 2008 8:05 pm    Post subject:
Reply with quote

mrrockford wrote:
DONE!


Roger that!

Back to top
View users profile Send private message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4845
Location: USA

PostPosted: Sat Feb 02, 2008 10:36 am    Post subject:
Reply with quote

FYI...

- http://www.securityfocus.com/news/11504
2008-02-01 - "In an ongoing attack, students and faculty at nearly a dozen universities and colleges have been targeted by phishing e-mails since the middle of January. The e-mail messages masquerade as missives from each school's help desk, asking that the student confirm their uname and password as well as requesting more personal information, including date of birth and country of origin... Schools targeted include Columbia University, Duke University, Princeton University, Purdue University, and the University of Notre Dame. The e-mail accounts of students and faculty that fall prey to the fraud are used, in most cases, to send out further spam as part of a lottery scam, Pearson and IT administrators stated. The attack may have already hit European schools earlier in the month, one university IT administrator stated on a security mailing list... Phishing attacks targeted at a specific subset of people, while fairly common in the corporate world and against banking customers, have not often been used against students. Princeton and other schools sent out warnings to their students and faculty about the attacks and stressed that users should never give out sensitive information or passwords to other people..."

.


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Sat Feb 02, 2008 11:36 am    Post subject:
Reply with quote

AplusWebMaster wrote:
FYI...

- http://www.securityfocus.com/news/11504
2008-02-01 - "In an ongoing attack, students and faculty at nearly a dozen universities and colleges have been targeted by phishing e-mails since the middle of January. The e-mail messages masquerade as missives from each school's help desk, asking that the student confirm their uname and password as well as requesting more personal information, including date of birth and country of origin... Schools targeted include Columbia University, Duke University, Princeton University, Purdue University, and the University of Notre Dame. The e-mail accounts of students and faculty that fall prey to the fraud are used, in most cases, to send out further spam as part of a lottery scam, Pearson and IT administrators stated. The attack may have already hit European schools earlier in the month, one university IT administrator stated on a security mailing list... Phishing attacks targeted at a specific subset of people, while fairly common in the corporate world and against banking customers, have not often been used against students. Princeton and other schools sent out warnings to their students and faculty about the attacks and stressed that users should never give out sensitive information or passwords to other people..."

.


Jack,
You can add the new information to the comment section of the article on the front page.

Back to top
View users profile Send private message
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Sat Feb 02, 2008 11:45 am    Post subject:
Reply with quote

CastleCops Link/a6873-Universities_in_the_US_being_targeted_in_a_Spear_Phishing_attack.html

GO THERE.


_________________
I wish you all the best and nothing less.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer