Educause Security Discussion mailing list archives

University e-mail addresses dumped to pastebin


From: "Justin C. Klein Keane" <jukeane () SAS UPENN EDU>
Date: Tue, 2 Aug 2011 08:23:42 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

  Just an FYI to concerned folks:  I noticed this morning that some
genius had polled the University of Washington directory and dumped all
the e-mail addresses they found to pastebin.  I fired off a few e-mails
to the staff at UW but haven't heard anything back yet.  Not sure what
folks are doing in terms of throttle control or anti-automation on their
directory services, but this is probably a precursor to a wider attack
against edu resource.  The e-mail on full-disclosure reads:

Came across this: http://www.washington.edu/home/peopledir/

I dumped most emails here

http://pastebin.com/ALYtW4hA

and is archived at http://seclists.org/fulldisclosure/2011/Aug/3

- --
Justin C. Klein Keane

Information Security and Unix Systems
University of Pennsylvania, School of Arts and Sciences

The digital signature on this e-mail may be confirmed using the
PGP key located at: http://www.sas.upenn.edu/computing/user/kleinkeane
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJON+xOAAoJEIH7slQlJAgK7G8P/isf6DaU1fnMY7SOecRV6fWB
Rw0M5idNGdH3ameDBBsTl8BSz7Tvt2iEfskOtMaQIrR4F9JQlri468Z4oiYposWl
nlhuSRxA8URiPGJ8tcOcKabk1F1tV3lNOSpaVetnpq91ex8R20o8mrbPY1SLHzEi
mlp5zDEUhjVqhprX2swKOpNxMWPA3xm80UkAoeMGzSKL7FtFI1V9W41ovUt5Mu69
D3pFbr5LoGltGIwvk5pxyEeJv2o5yxekdfcGoAw5YCD7VuXF58i8oE+4DBIWfg9Y
XaUsWRwivhVhrvwkC41janfUTba8GhLXKY8Zw4Kn66hv6ceW9LDBM9lx54Fiv/U2
WJ/YyCiS8RUmoxvXUkaMSLHyMc2s1+Y/HAgTHy9xF3BiP5KqDZRLEGSlA2GM5Ad8
ace9YhwcJJmybS8GXXYqCVOZGpujZxbXNh9GqUccZMcdlTL9FTjTFQ97Rr3WB0Bn
9aszsG8yS/N9BN8dRiDjNER4/abexZaOXJuTbez1YcIPtUhCJjDjcZ/W1NdJYULm
jbbAscfJTuf7Ohulp8LX/hFgUlmF+LVB+UjTxiW3Ugk2nQI181zv8jjMk8l2oevn
+y41KcsPG0wbEuc/hPEMBvALmAThWnrOzx+PVS9+zIBfPIVL448qZJlSIrEyWza+
T+kal31C5CFFZunZQb3v
=byhE
-----END PGP SIGNATURE-----


Current thread: