Educause Security Discussion mailing list archives

user account compromise?


From: "Barros, Jacob" <jkbarros () GRACE EDU>
Date: Thu, 24 Apr 2008 15:59:47 -0400

Beginning around 5:30pm yesterday, SPAM messages were sent from a student's
user account. The student claims to not know what is happening.. and I think
believe him.  He actually sent an email about the problem to our helpdesk at 1
am because he was getting so many delayed delivery and NDR messages. We are
still examining his laptop.

So far my assumption is that his account was compromised as copies of the
message are actually in his sent items and drafts folders.  Anyone disagree
with that assumption?  Sounds like a ludicrous question but is there any way I
can track who was using his account?

Also, I am unsure how to respond to the situation and no applicable policies
are in place.  Should campus departments or otherwise be notified of the
compromise?  Any non-internal legal ramifications here, i.e. I am getting many
responses from users who received the message.  Should I reply to them?  Does
that imply that we claim responsibility?  Should I mention that it actually
was our fault when I try to get off the blacklists we are already on?

Is this topic better suited for the email admin discussion group?  Any advice
or shared experience would be appreciated.

Jake Barros
Grace College



Attachment: smime.p7s
Description:


Current thread: