Feeds

University admins lend phishers a hand

Hacked cluster serves up addresses

Boost IT visibility and business value

Lax security at Indiana University appears to have played a key role in highly targeted phishing attack last year that hauled in confidential information on as many as 80 account holders of the school's credit union. The finding, gleaned through public records unearthed by a university student, provides an interesting case study in the resourcefulness phishers bring to their trade.

Among those who received the 2006 email purporting to come from officials with the IU Credit Union was Christopher Soghoian, a graduate student of computer security who wanted to know how his email address was targeted even though it had never been used. University officials rebuffed his attempts to learn more about the attack, so he filed a request under Indiana's public records act.

It turns out the perpetrators, who had ties with a machine in China, gained unauthorized access to the university's cluster of computers reserved for research projects, according to university documents. Once in, the attackers rifled through the cluster's /etc/passwd file, which revealed email addresses and other information on as many as 30,000 active users, including Soghoian, despite his never having applied for an account.

The university cluster not only gave up information that proved crucial in carrying out a successful spear phishing attack. It also provided the ideal cover to help the attackers bypass spam filters. It further proved a useful place to stash hacker tools used in other attacks, including ones that targeted account holders of the Florida Commerce Credit Union and the Sandia Laboratory Federal Credit Union, according to Soghoian.

No word yet on whether admins have tightened security on IU's system. ®

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?