Plan Finder Complete Guide Articles and Reviews Downloads About Us
Email Service Guide

Phishing attack targets Outlook Web Access

Comments Off
October 19th, 2009
Viktor Petersson
Screenshot from the Websense's Alert.

Screenshot from the Websense's Alert.

While this attack might not be very technical (we’ve seen these kinds of attacks for many years), I still think it is a brilliant attack. What makes the attack brilliant is that it does not use a generic fake page. WebSense Security Alert states that:

The malicious site is also very believable. The victim’s domain is used as a sub-domain to the site so that the attack site appears to be the victim’s actual OWA site. The victim’s domain name and email address are also used in a number of locations on the malicious site to make it that much more believable.

According to the above alert, the attack is fairly extensive with ’30,000 of these messages per hour’ and it is likely to slip through anti-virus filters.

With more companies making the switch from Desktop applications to web-based applications, I think we will see an increasing amount of attacks. Moreover, with simple techniques such as reading the identification string of the server (e.g. through IMAP), the attacker can customize the attack to suit the victims server. If it’s an Exchange server, the attacker can send the above page. If it’s a Zimbra server, the user can send a similar page, but based on the Zimbra design.

Be Sociable, Share!
  • Tweet
Tags: Exchange, Outlook, phishing, scam Posted in News Comments Off

Comments are closed.

  • RSS Feed
  • Facebook Fan
  • Twitter Feed

Latest Articles

  • 05/21 - This blog is more or less deprecated
  • 08/02 - Opolis — Revolutionary or just another email client?
  • 06/03 - Why your company shouldn’t move to Microsoft BPOS
  • 03/05 - reMail goes Open Source! What does it mean?
  • 02/15 - Email Marketing Part 4: 25 Tips To Optimize Your Campaign
  • 02/03 - Email Marketing Pt. 3: MadMimi, Aweber, Benchmark, iContact, CampaignMonitor Reviews
  • 01/28 - Atmail 6.1.3 is out. Now supports LDAP and Active Directory
  • 01/28 - Email Marketing Pt 2: MailChimp, ConstantContact, EmailBrain, LetterPop Reviews
  • 01/26 - Making Facebook’s messaging system IMAP compatible
  • 01/26 - Pegasus Mail 4.52 is out

Sponsored Link: Chronicle.im

The easy way to keep a diary or journal that goes with you wherever you go. All web, no downloads, totally free.
Chronicle.im Journal App


Sponsored Link: YippieMove

Need to transfer email between accounts? The YippieMove email migration tool lets you do that easily online.


Tags

    ActiveSync Android AOL apocalypse Atmail chat client collaboration Exchange Facebook FastMail.FM Gmail Gmail Labs Google Google Apps Google Wave Hotmail Hushmail IBM IMAP iNotes iPhone LotusLive Microsoft mobile Mozilla Open-Xchange Outlook phishing POP3 reMail review SaaS security social network spam T-Mobile threadsy Thunderbird Twitter VMware Windows Live Yahoo Zenbe Zimbra


Archives

  • May 2011
  • August 2010
  • June 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009

Connect with us!

  • Suggest an article
Got feedback, questions? Contact us. Advisory information only. Data may not be current or correct, prices and terms are based on our best interpretation of relevant user agreements. Database includes both affiliated and non affiliated providers. © 2009 WireLoad, LLC