<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ID Theft Product &#187; 1524</title>
	<link>http://idtheftproduct.com</link>
	<description>Mailboxes, Shredders, Software &#38; Services</description>
	<pubDate>Fri, 21 Dec 2007 21:29:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
	<language>en</language>
			<item>
		<title>OWA Fishing attack</title>
		<link>http://idtheftproduct.com/2007/12/10/owa-fishing-attack/</link>
		<comments>http://idtheftproduct.com/2007/12/10/owa-fishing-attack/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 09:00:00 +0000</pubDate>
		<dc:creator></dc:creator>
		
		<category><![CDATA[1524]]></category>

		<guid isPermaLink="false">http://idtheftproduct.com/2007/12/10/owa-fishing-attack/</guid>
		<description><![CDATA[I just love Gnucitizen - this time Adrian Pastor explains how to use an Outlook Web Access design flaw to create a phishing attack. 
The post is a bit technical, but it gives you a very good idea of just how easy it is to fool your OWA users to give up their user names / [...]]]></description>
			<content:encoded><![CDATA[<p>I just love Gnucitizen - this time Adrian Pastor explains how to use an <a href="http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users">Outlook Web Access design flaw to create a phishing attack</a>. </p>
<p>The post is a bit technical, but it gives you a very good idea of just how easy it is to fool your OWA users to give up their user names / passwords to a hacker. </p>
<p>The scary bit is that Adrian told Microsoft about this a couple of years ago - but since this is a design feature and not a bug, Microsoft is not changing it. </p>
<p>So if you are running OWA - make sure to take precautions!  </p>
<div>
<div>Bookmark/Search this post with: </div>
<p><a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;title=OWA+Fishing+attack" title="Bookmark this post on del.icio.us." rel="nofollow"><img src="/modules/service_links/delicious.png" alt="delicious" /></a> | <a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;title=OWA+Fishing+attack" title="Digg this post on digg.com." rel="nofollow"><img src="/modules/service_links/digg.png" alt="digg" /></a> | <a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;title=OWA+Fishing+attack" title="Submit this post on reddit.com." rel="nofollow"><img src="/modules/service_links/reddit.png" alt="reddit" /></a> | <a href="http://ma.gnolia.com/bookmarklet/add?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;title=OWA+Fishing+attack" title="Submit this post on ma.gnolia.com." rel="nofollow"><img src="/modules/service_links/magnoliacom.png" alt="magnoliacom" /></a> | <a href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;h=OWA+Fishing+attack" title="Submit this post on newsvine.com." rel="nofollow"><img src="/modules/service_links/newsvine.png" alt="newsvine" /></a> | <a href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack&amp;t=OWA+Fishing+attack" title="Submit this post on furl.net." rel="nofollow"><img src="/modules/service_links/furl.png" alt="furl" /></a> | <a href="http://technorati.com/cosmos/search.html?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack" title="Search Technorati for links to this post." rel="nofollow"><img src="/modules/service_links/technorati.png" alt="technorati" /></a> | <a href="http://blogs.icerocket.com/search?q=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2FOWA_fishing_attack" title="Search IceRocket for links to this post." rel="nofollow"><img src="/modules/service_links/icerocket.png" alt="icerocket" /></a></div>
<p><a href="http://feeds.feedburner.com/~a/kairoer?a=khRb6l"><img src="http://feeds.feedburner.com/~a/kairoer?i=khRb6l" border="0"></img></a></p>
<div>
<a href="http://feeds.feedburner.com/~f/kairoer?a=RkncCaC"><img src="http://feeds.feedburner.com/~f/kairoer?i=RkncCaC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=csGPkQC"><img src="http://feeds.feedburner.com/~f/kairoer?i=csGPkQC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=NaZSAic"><img src="http://feeds.feedburner.com/~f/kairoer?i=NaZSAic" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=L9T7Y3c"><img src="http://feeds.feedburner.com/~f/kairoer?i=L9T7Y3c" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=PLJmnsc"><img src="http://feeds.feedburner.com/~f/kairoer?i=PLJmnsc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=vBnkiLC"><img src="http://feeds.feedburner.com/~f/kairoer?i=vBnkiLC" border="0"></img></a><br />
 <a href="http://feeds.feedburner.com/~f/AmbersailSecNews?a=m9MNo6C"><img src="http://feeds.feedburner.com/~f/AmbersailSecNews?i=m9MNo6C" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AmbersailSecNews?a=VE7EuJC"><img src="http://feeds.feedburner.com/~f/AmbersailSecNews?i=VE7EuJC" border="0"></img></a> </div>
<p><img src="http://feeds.feedburner.com/~r/kairoer/~4/197957433" height="1">
<p>Original post by <em><a href="http://feeds.feedburner.com/~r/kairoer/~3/197957433/OWA_fishing_attack" title="">Yahoo! News Search Results for identity theft</a></em></p>
<h3>Additional Reading</h3><ul class="related_post"><li><a href="http://idtheftproduct.com/2007/12/14/state-law-takes-aim-at-identity-theft-gresham-outlook/" title="State law takes aim at identity theft (Gresham Outlook)">State law takes aim at identity theft (Gresham Outlook)</a></li><li><a href="http://idtheftproduct.com/2007/09/03/intelligent-questioning/" title="Intelligent Questioning">Intelligent Questioning</a></li><li><a href="http://idtheftproduct.com/2007/12/12/permanent-link-for-ipfw-rules/" title="Permanent Link For ipfw Rules">Permanent Link For ipfw Rules</a></li><li><a href="http://idtheftproduct.com/2007/12/17/uk-loses-data-of-3-million-learner-drivers/" title="UK loses data of 3 million learner drivers">UK loses data of 3 million learner drivers</a></li><li><a href="http://idtheftproduct.com/2007/12/13/web-site-of-the-french-embassy-in-libya-under-attack/" title="Web Site of the French Embassy in Libya Under Attack">Web Site of the French Embassy in Libya Under Attack</a></li><li><a href="http://idtheftproduct.com/2007/12/18/pid-controlled-popcorn-popper-coffee-roaster/" title="PID controlled popcorn popper coffee roaster">PID controlled popcorn popper coffee roaster</a></li><li><a href="http://idtheftproduct.com/2007/12/06/a-call-for-rational-discourse-on-identity-theft-zdnet/" title="A call for rational discourse on identity theft (ZDNet)">A call for rational discourse on identity theft (ZDNet)</a></li><li><a href="http://idtheftproduct.com/2007/12/09/mourning-the-passing-of-a-good-friend/" title="Mourning the passing of a good friend">Mourning the passing of a good friend</a></li><li><a href="http://idtheftproduct.com/2007/12/07/stupid-safety-feature-of-the-week/" title="Stupid Safety Feature Of The Week">Stupid Safety Feature Of The Week</a></li><li><a href="http://idtheftproduct.com/2007/12/07/report-cybercrime-stormed-the-net-in-2007/" title="Report: Cybercrime Stormed the Net in 2007">Report: Cybercrime Stormed the Net in 2007</a></li></ul><!-- Created with WP-Autoblog (http://elliottback.com) -->]]></content:encoded>
			<wfw:commentRss>http://idtheftproduct.com/2007/12/10/owa-fishing-attack/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.210 seconds -->
