Monday, September 22, 2008

Phishing, again

We've gotten another round of those phishing emails, asking for MySCSU email info.
DO NOT respond!
IT does not ask for info this way. If you did respond, get in touch with the Helpdesk right away (helpdesk@southernct.edu or 203-392-5123). You also should change your password. NOW.

I've gotten a bunch of these on different email accounts; they are exactly alike, except for the domain name of the email. No IT or technical support department asks for info like this. If you get something like this and aren't sure, go to your email, IT, or IPS website (via your own bookmarks or web search, not a link in the email) and find the help links. If possible, forward them the email, so that they can tell if it was legitimate.

Stay safe, folks.

Labels: , ,

Tuesday, August 26, 2008

IDs, and passwords, and phishing, oh, my!

Yep, it's the beginning of the semester, and time for the annual password post!

Not much has changed from last year. We still have 2 ID's: username (lastname-first initial-number, such as hedreenr1) and ID number (70XXXXXX). Your username is used for MySCSU and the campus network log on. The ID number is used for BannerWeb and the Library. Each application has it's own password, meaning that each ID has 2 passwords associated with it.

MySCSU: Username and 8+ character password using letters, numbers, "special characters", and/or capitalization. Passwords expire every 90 days. This username/password combination is also used for the Vista elearning system (Blackboard Vista). Password Reset Instructions (faculty and online students, call the helpdesk)
Network log on: Username and 8+ character password using letters, numbers, "special characters", and/or capitalization. Passwords expire every 90 days. Password Reset
BannerWeb: ID number and 6 character password (I think the Banner upgrade this summer now allows more than 6 characters.) Passwords were expiring every semester, but I didn't notice it this time. The Banner password reset form is gone from the helpdesk website, so call the helpdesk.
Library: ID number and 4+ character password, usually refered to as the Library PIN, using only number and/or letters, no "special characters". Passwords/PINs do not expire. Call or visit the Circulation Desk to delete forgotten PINs. More help.

I was wondering if something like this image would help?

And finally, we got some obnoxious phishing emails this summer--remember that IT will NEVER ask you for your ID's and/or passwords via email. If you get such an email, discard it immediately. If you are uncertain, contact the Helpdesk directly (NOT via any link in the email--go to http://helpdesk.southernct.edu/ ) and ask if there is a problem. They might ask you to forward the email to them.

Have a good semester, folks!

Labels: , , , , ,

Monday, July 21, 2008

Spam warning

I think this is our first campus specific spam. The Office of Information Technology send the following warning this morning:

To All Faculty and Staff,

Several people have reported the receipt of an email with the subject “FINAL NOTIFICATION!!!” that appears to come from the “SOUTHERNCT WEBMAIL SUPPORT TEAM [supportteam@southernct.edu]”. The message itself is as follows:

Dear SOUTHERNCT Webmail Subscriber

This mail is to inform all our {SOUTHERNCT} webmail users that we will be maintaining and upgrading our website in a couple of days from now.As a Subscriber you are required to send us your Email account details to enable us know if you are still making use of your mailbox. Be informed that we will be deleting all mail account that is not functioning to enable us create more space for new subscribers, You are to send your mail account details which are as follows:

*User Name:

*Password:

Failure to do this will immediately render your email address deactivated from our database.

Thank you for using SOUTHERNCT

FROM THE SOUTHERNCT SUPPORT TEAM

Please be advised that this email is spam. It is a phishing scheme designed to get your username and password. Do not reply to this. Simply delete it.

Unfortunately, the timing of our Microsoft Exchange implementation makes this message more confusing and believable. However, please be advised that the OIT staff will never send an email out asking you for your username and password. Also, another clue that this is not legitimate is that OIT will not send emails out with all upper case letters in the “Subject” header.

We will be investigating this email and will try to include it in our spam gateway rules.

Thank you for your continued vigilance in privacy, security, and malware issues.

The OIT Staff
You should never respond to any email requesting your account password. Real IT folks have access to our accounts--they don't need our passwords. The only situation I can think of where an IT help staffer has ever asked me for a password was at the end of a long, multi-email and phone exchange trying to figure out why what I saw looked different than what she saw. No service or site worth anything would send a request like this with no previous contact.

Another clue about this, by the way, is the curly brackets around the SOUTHERNCT in the first sentence. Spammers exchange "form letter" type texts, usually copied from legitimate sources, with the information that needs replacing marked in some sort of bracket. I actually got one where the spammer didn't replace anything, so it was addressed, "Dear {eBay username}". The hint about the capitalization in the subject is excellent. It's true, very few legitimate business-type emails come through with all caps subject lines.

Be smart and stay safe--if you get a suspicious email like this, go to the site that it's supposed to be from (NOT via any link in the email--use a search engine if you don't know the URL), find the help or contact information, and write or call directly to the institution/company.

And, of course, if you did get this and did respond, contact the helpdesk (which is helpdesk@southernct.edu, not supportteam) IMMEDIATELY!

Labels: , , , , ,