Jump to content

Recommended Posts

Posted

Hi All

 

we are getting a password spray attack on our office 365 account, although the measures we have in place are effective at blocking them I am now changing the 365 access to be only form specific IP addresses, we use LGFL but I am not sure where to get the public IP or any IP details so I can add them as allowed IP's, I couldn't call LGFL today, on Meraki I am seeing a 5.150 address not sure if that the main one, I will be checking on the router now as its been a long time since I setup the LGFL connection.

 

also any advise on the password spray attack would be much appreciated.

 

Thanks!

Posted (edited)

Hi @xicor

 

Do you mean you want it so you can only login from LGfL IPs, just your schools one or similar?

 

Can't suggest anything regarding password spraying other than making sure passwords are not generic, can't tell you how many times over the years I've seen 'bursar' accounts with the password of bursar or 'schoolname' and thats going to be an easy catch.

 

Thanks

Paddy

Edited by PaddyNewman
  • Thanks 1
Posted
Hi @xicor, you can find your public LGfL IP address in the support site under My Account > LGfL 2.0 Deployment Details > IP Address Details page (I think that's the correct name of all the pages). It will most likely be the one you've already identified as 5.150.x.x
  • Thanks 2
Posted

Hi All, just an FYI regarding the password spray attack

 

I've disabled SharePoint from being accessed from any external non-school lgfl IP and I've setup a security policy that forces the user to sign out if a successful attempt to login was made, I've also disabled all non-modern authentication from o365 and set several client access rules from powershell, though I'm still waiting to see those come into effect, also I changed the UPN's of all affected users while retaining their old reply/main email accounts, that stopped the attack almost immediately!

 

I'm now looking into two factor authentication via rsa keys/fob and combine that with a Meraki VPN so that staff can only access anything from the LGFL network with two factor, its been a long weekend........

Posted

Hi Paddy, it was just for my school, all sorted now though, Thanks

 

Hi @xicor

 

Do you mean you want it so you can only login from LGfL IPs, just your schools one or similar?

 

Can't suggest anything regarding password spraying other than making sure passwords are not generic, can't tell you how many times over the years I've seen 'bursar' accounts with the password of bursar or 'schoolname' and thats going to be an easy catch.

 

Thanks

Paddy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...