Re: Phishing

Mathew Want <[email protected]> Fri, 12 Apr 2013 16:49:03 +1000
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <CAKFczxYEtu9h-OX=hVb+yaV-kxS0iHnXYR+5q0B+grysBsCx7Q@mail.gmail.com>
--===============0504989778==
Content-Type: multipart/alternative; boundary=14dae93a172378e7aa04da244ca8

--14dae93a172378e7aa04da244ca8
Content-Type: text/plain; charset=ISO-8859-1

Last time they sent out a warning email here along the lines of:

<warning_email>
We never ask for your username and password. If you get an email that looks
like:

"There is an issue with your account. Please reply with your username and
password and we will rectify it"

You should never reply to these messages with your details/
</warning_email>

50 people replied with their usernames and passwords. As much as user
education should be the answer, you cant put brains in pumpkins and you can
patch stoopid.

*sigh*. Looks like the only real answer is to have your systems set up in
such a way that when there is a compromise from this type of thing, they
cant do any damage or it is at least restricted. This is starting to sound
like a song we have sung before.....

Have a pleasant weekend all!

M@
-- 
"Some things are eternal by nature,
others by consequence"

On 11 April 2013 19:38, Paul D. Robertson <[email protected]> wrote:

> I've had friends tell me that they've never failed using fake LinkedIn
> accounts when performing pen tests- I'm not sure how valuable training is,
> but I'm reasonably confident it and Facebook are the top two common vectors.
>
> Paul
> --
> President and Chairman, FluidIT Group
> Moderator, Firewall-Wizards
> http://pauldrobertson.net
> http://pauldrobertson.com
> @compuwar
>
> On Apr 10, 2013, at 18:56, Dotzero <[email protected]> wrote:
>
> > Training is useful as long as it is appropriate training that the
> > enduser can reasonably implement.
> >
> > As far as blocking Facebook/LinkedIn, I don't believe it is a
> > particularly useful approach. I prefer to educate endusers on ways to
> > mitigate risks.
> >
> > An example of this is to never click on purported LinkedIn emails.
> > Delete them and log into the site to check the message. Another
> > example is to never accept an invitation to link from someone you
> > don't know unless someone you know vouches for them. Taking these
> > sorts of steps significantly reduces potential risks.
> >
> > I do recommend applying SPF/DKIM/DMARC validation to inbound mail
> > streams. ISPs and mailbox providers such as Gmail, Yahoo! and AOL are
> > ahead of enterprises in doing this. Inbound email authentication
> > validation adds a layer of protection to protect your users and
> > organization. If you have a brand/domain at risk it is useful to
> > implement on the sending side to help protect your customers, partners
> > and vendors.
> >
> > Reporting malicious URLs and redirectors that arrive in your inbox(s)
> > or traps to APWG is useful as is reporting them to the abuse contact
> > in whois or to the upstream provider.
> >
> > A good practice is to also implement BCP38 outbound filtering. It
> > protects your reputation and ultimately helps everyone else from abuse
> > eminating from your network.
> >
> > Just a few thoughts,
> >
> > Mike
> >
> > On Wed, Apr 10, 2013 at 5:52 PM, Paul D. Robertson <[email protected]>
> wrote:
> >> Outside of constant training and blocking Facebook/LinkedIn does anyone
> have any good pointers or tools for phishing/spear phishing threats?
> >>
> >> Paul
> >> --
> >> President and Chairman, FluidIT Group
> >> Moderator, Firewall-Wizards
> >> http://pauldrobertson.net
> >> http://pauldrobertson.com
> >> @compuwar
> >> _______________________________________________
> >> firewall-wizards mailing list
> >> [email protected]
> >> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> > _______________________________________________
> > firewall-wizards mailing list
> > [email protected]
> > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>

--14dae93a172378e7aa04da244ca8
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div><div><div><div>Last time they sent out=
 a warning email here along the lines of:<br><br>&lt;warning_email&gt;<br>W=
e never ask for your username and password. If you get an email that looks =
like:<br>
<br></div>&quot;There is an issue with your account. Please reply with your=
 username and password and we will rectify it&quot;<br><br></div>You should=
 never reply to these messages with your details/<br></div>&lt;/warning_ema=
il&gt;<br>
<br></div>50 people replied with their usernames and passwords. As much as =
user education should be the answer, you cant put brains in pumpkins and yo=
u can patch stoopid. <br><br></div>*sigh*. Looks like the only real answer =
is to have your systems set up in such a way that when there is a compromis=
e from this type of thing, they cant do any damage or it is at least restri=
cted. This is starting to sound like a song we have sung before.....<br>
<br></div>Have a pleasant weekend all!<br><br></div>M@<br><div class=3D"gma=
il_extra">-- <br>&quot;Some things are eternal by nature,<br>others by cons=
equence&quot;<br><br><div class=3D"gmail_quote">On 11 April 2013 19:38, Pau=
l D. Robertson <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" t=
arget=3D"_blank">[email protected]</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">I&#39;ve had friends tell=
 me that they&#39;ve never failed using fake LinkedIn accounts when perform=
ing pen tests- I&#39;m not sure how valuable training is, but I&#39;m reaso=
nably confident it and Facebook are the top two common vectors.<br>

<div class=3D"im"><br>
Paul<br>
--<br>
President and Chairman, FluidIT Group<br>
Moderator, Firewall-Wizards<br>
<a href=3D"http://pauldrobertson.net" target=3D"_blank">http://pauldroberts=
on.net</a><br>
<a href=3D"http://pauldrobertson.com" target=3D"_blank">http://pauldroberts=
on.com</a><br>
@compuwar<br>
<br>
</div><div class=3D""><div class=3D"h5">On Apr 10, 2013, at 18:56, Dotzero =
&lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<b=
r>
<br>
&gt; Training is useful as long as it is appropriate training that the<br>
&gt; enduser can reasonably implement.<br>
&gt;<br>
&gt; As far as blocking Facebook/LinkedIn, I don&#39;t believe it is a<br>
&gt; particularly useful approach. I prefer to educate endusers on ways to<=
br>
&gt; mitigate risks.<br>
&gt;<br>
&gt; An example of this is to never click on purported LinkedIn emails.<br>
&gt; Delete them and log into the site to check the message. Another<br>
&gt; example is to never accept an invitation to link from someone you<br>
&gt; don&#39;t know unless someone you know vouches for them. Taking these<=
br>
&gt; sorts of steps significantly reduces potential risks.<br>
&gt;<br>
&gt; I do recommend applying SPF/DKIM/DMARC validation to inbound mail<br>
&gt; streams. ISPs and mailbox providers such as Gmail, Yahoo! and AOL are<=
br>
&gt; ahead of enterprises in doing this. Inbound email authentication<br>
&gt; validation adds a layer of protection to protect your users and<br>
&gt; organization. If you have a brand/domain at risk it is useful to<br>
&gt; implement on the sending side to help protect your customers, partners=
<br>
&gt; and vendors.<br>
&gt;<br>
&gt; Reporting malicious URLs and redirectors that arrive in your inbox(s)<=
br>
&gt; or traps to APWG is useful as is reporting them to the abuse contact<b=
r>
&gt; in whois or to the upstream provider.<br>
&gt;<br>
&gt; A good practice is to also implement BCP38 outbound filtering. It<br>
&gt; protects your reputation and ultimately helps everyone else from abuse=
<br>
&gt; eminating from your network.<br>
&gt;<br>
&gt; Just a few thoughts,<br>
&gt;<br>
&gt; Mike<br>
&gt;<br>
&gt; On Wed, Apr 10, 2013 at 5:52 PM, Paul D. Robertson &lt;<a href=3D"mail=
to:[email protected]">[email protected]</a>&gt; wrote:<br>
&gt;&gt; Outside of constant training and blocking Facebook/LinkedIn does a=
nyone have any good pointers or tools for phishing/spear phishing threats?<=
br>
&gt;&gt;<br>
&gt;&gt; Paul<br>
&gt;&gt; --<br>
&gt;&gt; President and Chairman, FluidIT Group<br>
&gt;&gt; Moderator, Firewall-Wizards<br>
&gt;&gt; <a href=3D"http://pauldrobertson.net" target=3D"_blank">http://pau=
ldrobertson.net</a><br>
&gt;&gt; <a href=3D"http://pauldrobertson.com" target=3D"_blank">http://pau=
ldrobertson.com</a><br>
&gt;&gt; @compuwar<br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; firewall-wizards mailing list<br>
&gt;&gt; <a href=3D"mailto:[email protected]">firewall=
[email protected]</a><br>
&gt;&gt; <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall=
-wizards" target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/=
firewall-wizards</a><br>
&gt; _______________________________________________<br>
&gt; firewall-wizards mailing list<br>
&gt; <a href=3D"mailto:[email protected]">firewall-wiz=
[email protected]</a><br>
&gt; <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wiz=
ards" target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/fire=
wall-wizards</a><br>
_______________________________________________<br>
firewall-wizards mailing list<br>
<a href=3D"mailto:[email protected]">firewall-wizards@=
listserv.icsalabs.com</a><br>
<a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"=
 target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-=
wizards</a><br>
</div></div></blockquote></div><br><br clear=3D"all"><br><br>
</div></div>

--14dae93a172378e7aa04da244ca8--

--===============0504989778==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0504989778==--