Educause Security Discussion mailing list archives

Re: Compromised Accounts Procedures


From: "Bidwell, Lesley" <Lesley.Bidwell () ONEONTA EDU>
Date: Wed, 23 May 2012 15:06:42 -0400

We follow a similar process and also verify that no rules have been added to mail accounts to forward or delete 
messages.  

Lesley A. Bidwell
Director of Networking and Telecommunications Services
SUNY College at Oneonta
607 436 2628
Lesley.Bidwell () oneonta edu


-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Rich 
Graves
Sent: Wednesday, May 23, 2012 2:25 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Compromised Accounts Procedures

When I become aware of an account compromise, I (run a script to) disable the password and create a ticket (in 
WebHelpDesk.com) with a few custom fields, below. The user *must* go through the helpdesk because self-service 
challenge questions and SMS callbacks could be changed with password alone.

The "How Compromised?" question is required. We only started doing this a few months ago, so I don't know how useful 
the metrics are going to be. The other questions are optional, just to remind helpdeskers what to do.

  How Compromised?
  () Phishing  () Malware  () Disclosed to a "Friend" () Other (specify in notes) () Unknown

  Client has been told their password must be completely different than the original?
  () No  () Yes

  Instruct client to change password on:
    [] Handhelds
    [] Mail Clients
    [] Restart Workstation

Phishing accounts for the vast majority, but we have had a few passwords presumed disclosed by malware, and a case 
where a student was sharing their password to a parent, raising questions of online quiz integrity. Yes, we've seen 
several cases where password was phished, student resets their password to something that differs from the original by 
only one digit, repeat.

Current thread: