OWA Fishing attack

Submitted by Kai on Mon, 2007-12-10 11:00.

I just love Gnucitizen - this time Adrian Pastor explains how to use an Outlook Web Access design flaw to create a phishing attack

The post is a bit technical, but it gives you a very good idea of just how easy it is to fool your OWA users to give up their user names / passwords to a hacker.

The scary bit is that Adrian told Microsoft about this a couple of years ago - but since this is a design feature and not a bug, Microsoft is not changing it.

So if you are running OWA - make sure to take precautions!  

Post new comment

The content of this field is kept private and will not be shown publicly.

Navigation

Recent comments

Recent blog posts


The blogger is Kai Roer, a European Information security professional.

View Kai Roer's profile on LinkedIn

Lijit

Resources

Archive

Explore Security Bloggers Network (a FeedBurner Network)