Jump to content

Recommended Posts

Posted

Gotta feel kinda sorry for whoever is responsible for this blunder, very glad that my mistakes don't make the national media. All for the sake of the "Only accept mail from authenticated senders" check-box on your all students mailing list.

 

#BelloGate: Thousands of UCL students sent YouPorn, Ukip and Sarah Palin links in email hack - News - Gadgets and Tech - The Independent

 

Our librarian is a student there and forwards her UCL email to her school email, 2700 emails in her inbox this morning!

  • Thanks 2
Posted
My girlfriend works for UCL. Her email is provided by Office 365. It would be interesting to get a post mortem of this incident and see if other O365 tenants are vulnerable, assuming it was an O365 account that got comprised.
Posted

The way I understand it is that there was no hack/compromise, just a blind acceptance of mail to their all students distribution list. Some bright spark signed up said distribution list to all sorts of lovely x-rated services!

 

Then some students were hitting reply-all asking for the mails to stop which just added to the problem.

Posted (edited)

I think by default Exchange 2010 has 'Require that all senders are authenticated' on distribution groups.

 

I think this is imperative for generic distribution groups.

 

Also block students from sending to the distribution group and only let certain members of staff send to any mass distribution groups to lessen the surface for attack.

 

This is also the reason why you do not let everyone send mass group emails :doh:

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...