Educause Security Discussion mailing list archives

Re: Phishing E-mail Uptick???


From: Heath Barnhart <heath.barnhart () WASHBURN EDU>
Date: Mon, 24 Oct 2011 10:40:45 -0500

I haven't heard about any in recently, though my spam filters are probably catching them. We are using Barracuda which does rate limiting, virus check, RBL, and custom filtering on several parts of a message.


--
------------------------------------------------------------------------
Heath Barnhart, CCNA
Information Systems Services
Washburn Univeristy
Topeka, KS 66621

On 10/22/2011 10:08 PM, Gibson, Nathan J. (HSC) wrote:

Is any other campus just getting slammed with phishing e-mails? Specifically e-mails that say: "You have exceeded the size of your mailbox please login _here _to request a size increase".__

__

Then once the user gives their credentials away the attackers connect through outlook web access and sends out 10's of thousands of e-mails with that user's account causing all my smtp servers to get blacklisted.

I know this happens and we see it occasionally, but the last week has been insane. It's just been wave after wave. Just wondering if any other campus has seen an uptick in this attack as of late?

Also, if you wouldn't mind, could you share with me the products and/or methods you use to "rate limit" user outbound e-mails. Meaning......jdoe () somecollege edu can only send out 100 e-mails per hour.

*GIBBY*

_____________________________

Nathan J. Gibson, MsIA, CISSP, CISM,CCNA, MCSA

IT Architect

Infrastructure Services

The University of Oklahoma HSC

voice: 405.271.2644 x50340

fax:    405.271.2181

Feedback? Email comments to Chris Hodges <mailto:chris-hodges () ouhsc edu?subject=Feedback%20on%20Gibby>

--------------------------

CONFIDENTIALITY NOTICE: This e-mail communication and any attachments may contain confidential and privileged information for the use of the designated recipients named above. If you are not the intended recipient, you are hereby notified that you have received this communication in error and that any review, disclosure, dissemination, distribution or copying of it or its contents is prohibited. If you have received this communication in error, please destroy all copies of this communication and any attachments.





Current thread: