Educause Security Discussion mailing list archives

Re: .edu email phishing


From: Mike Iglesias <iglesias () UCI EDU>
Date: Wed, 2 Apr 2008 13:24:45 -0700

Dave Koontz wrote:
Tim, if you are running Barracuda (Spam Assassin) with ClamAV, check out
Sane Security's Phishing and Scam signatures.  They do a great job of
catching these phishing messages and most of the others out there (like
eBay, banks, etc.)   Just schedule an update to run periodically.

http://www.sanesecurity.co.uk/clamav/downloads.htm

We've started using these signatures recently, and they are working.  They
work a little *too* well, and have caused some of us to be dropped from some
mailing lists (like this one) because people are posting the phishing email
messages that have been sent to their campuses to the list (which I'm not
complaining about), the Sane Security rules catch them, and the email is
rejected during delivery.  After some number of delivery failures, Listserv
drops you from the list.  So either subscribe using an email address that
doesn't get run thru the rules or exempt this list (and any others that might
have sample phishing email posted to them) from rule checking.


--
Mike Iglesias                          Email:       iglesias () uci edu
University of California, Irvine       phone:       949-824-6926
Network & Academic Computing Services  FAX:         949-824-2270

Current thread: