Security Manager's Journal: Not-so-innocent email distribution lists
- 19 November, 2012 14:52
Is everything a potential security vulnerability? Is there nothing that a security manager shouldn't look at with suspicion?
At issue: A phishing attack gets through to 900 users on a single email distribution list.
Action plan: Find out how many email distribution lists are externally available.
What, for example, could seem more innocent than an email distribution list? Such lists are convenient and ubiquitous, and in a company of any size at all, indispensable. They let you send an email to everyone in, say, marketing, by just putting the name of the marketing group in your email's "to" field. You don't have to worry about leaving anyone out, as long as your company's Exchange or Notes administrator sees to it that the lists are kept up to date. They certainly don't seem suspect.
Last week, however, distribution lists were implicated when we looked into something that turned out to be a rather brazen phishing expedition.
It started with the help desk receiving emails from several employees complaining that they were unable to access our company's payroll website and that they had gotten emails stating that either the certificate used to access the payroll site had expired (and they needed to click on a link to validate the certificate) or the password for the site had expired (and they needed to log in to change the password). That sounded like phishing to me, and sure enough, when I moved my curser over the link in the email, a very different Web address was displayed.
Wanting to know more, we investigated the link. What we found was that any user who had done the same was encouraged to install a file. We then downloaded the file in a secure environment for forensic analysis and identified it as a piece of malicious software for connecting to a site in China. It looked as if the idea was to trick unsuspecting users into making their PCs available to a command-and-control network operated out of China. Fortunately, our endpoint protection client is able to detect the software and prevent it from executing. Unfortunately, at any given time, about 6% to 7% of our desktops are not protected or haven't been updated with the proper pattern files, so there is the possibility that some machines on our network are now zombies.
But what does any of this have to do with distribution lists? Well, the phishing email was sent to an externally available distribution list with more than 900 users. That made it easy for us to determine which machines might be compromised, so we'll be able to check each one and make sure it has the proper endpoint protection client installed.
Rein In Those Lists
There was no good reason for this distribution list to be externally available. That led me to ask our email administrators how many of our distribution lists are configured similarly. The answer was astonishing: We have more than 3,000 distribution lists (and just 4,000 employees, mind you), and more than 400 of them are externally available. I can't see any reason why our external partners would need more than 20 or 30 lists. Clearly, we have a process problem.
In fact, some of our help desk staffers have been marking distribution lists as externally available by default. They will be educated to do otherwise. We are also going to audit all of the externally available lists and eliminate any for which there is no business justification. From now on, no distribution list will be externally available without my approval.
To ensure compliance, I'm having our security analyst investigate whether we can use our security incident and event management tool to alert us when a newly created distribution list is marked as "externally available." I've also asked our email administrators to investigate why our external spam-filtering service didn't protect us from this attack. And finally, this is a great opportunity to send out a global email to warn everyone about phishing attacks and provide tips on how to spot one.
This week's journal is written by a real security manager, "Mathias Thurman," whose name and employer have been disguised for obvious reasons. Contact him at firstname.lastname@example.org.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Poison Ivy: Assessing Damage and Extracting Intelligence
- Mobility in Financial Services
- Casestudy: Managing an Antivirus Service and Improve the Customer Experience
- Choice and Control – Considerations for Developing Enterprise Cloud Strategies
- Defending Against Increasingly Sophisticated Cyber Attacks
The enlightened CIO’s guide to running projects
Why IT projects really fail
Queensland government to provide 200 services online by 2015
Call Centers Suffer From Big Data Overload
CIO 100: Carsales wins top gong for innovation
APAC Digital Performance
With some of the highest levels of social media penetration, mobile device ownership, and Internet connectivity in the world, Asian markets are ripe for more innovative and adept interactive engagement. In this study, we look at how marketers in the region express high hopes for digital, but hare held back with limited budgets and a region-wide lack of talent and training. Click for more
Multi-Factor Authentication; Current Usage and Trends
In this digital age, validating identities and controlling access is vital, which is why multifactor authentication has become such a fundamental requirement in so many organisations. This survey looks at the authentication landscape in Europe, the Middle East, and Africa, and offers insights into how it is expected to change in the coming years.
Eight Simple Steps to Boost Campaign Results Using Predictive Modelling
Marketers today are consumed by big data, struggling to find meaning and under pressure to use that meaningful data in smart ways to boost results. But many organizations are reluctant to try and use predictive modelling in their campaigns, due to unfamiliarity and the dependence on complex tools – yet with modern, marketing-friendly modelling tools, integrated with campaign management, it is easier than you think. This whitepaper demonstrates how predictive modelling plays a critical role in streamlining the selection process.