Educause Security Discussion mailing list archives

Phishing E-mail Uptick???


From: "Gibson, Nathan J. (HSC)" <Nathan-Gibson () OUHSC EDU>
Date: Sat, 22 Oct 2011 22:08:23 -0500

Is any other campus just getting slammed with phishing e-mails? Specifically e-mails that say: "You have exceeded the 
size of your mailbox please login here to request a size increase".

Then once the user gives their credentials away the attackers connect through outlook web access and sends out 10's of 
thousands of e-mails with that user's account causing all my smtp servers to get blacklisted.

I know this happens and we see it occasionally, but the last week has been insane. It's just been wave after wave.  
Just wondering if any other campus has seen an uptick in this attack as of late?

Also, if you wouldn't mind, could you share with me the products and/or methods you use to "rate limit" user outbound 
e-mails. Meaning......jdoe () somecollege edu can only send out 100 e-mails per hour.



GIBBY
_____________________________
Nathan J. Gibson, MsIA, CISSP, CISM,CCNA, MCSA
IT Architect
Infrastructure Services
The University of Oklahoma HSC
voice: 405.271.2644 x50340
fax:    405.271.2181
Feedback?  Email comments to Chris Hodges<mailto:chris-hodges () ouhsc edu?subject=Feedback%20on%20Gibby>
--------------------------
CONFIDENTIALITY NOTICE: This e-mail communication and any attachments may contain confidential and privileged 
information for the use of the designated recipients named above. If you are not the intended recipient, you are hereby 
notified that you have received this communication in error and that any review, disclosure, dissemination, 
distribution or copying of it or its contents is prohibited. If you have received this communication in error, please 
destroy all copies of this communication and any attachments.



Current thread: