<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ITS Security Blog</title>
	<atom:link href="http://it-security.usc.edu/feed/" rel="self" type="application/rss+xml" />
	<link>http://it-security.usc.edu</link>
	<description></description>
	<lastBuildDate>Fri, 17 May 2013 22:07:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Security Updates for iTunes</title>
		<link>http://it-security.usc.edu/2013/05/17/security-updates-for-itunes/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-updates-for-itunes</link>
		<comments>http://it-security.usc.edu/2013/05/17/security-updates-for-itunes/#comments</comments>
		<pubDate>Fri, 17 May 2013 22:07:40 +0000</pubDate>
		<dc:creator>mbordas</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[mac os x]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[software patches and updates]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=524</guid>
		<description><![CDATA[Apple released the latest version of iTunes (11.0.3) today, which includes a number of important security fixes.  The update addresses one vulnerability in the Apple OSX version, and forty-one vulnerabilities in the Windows version.  For more information, see About the security &#8230; <a href="http://it-security.usc.edu/2013/05/17/security-updates-for-itunes/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Apple released the latest version of iTunes (11.0.3) today, which includes a number of important security fixes.  The update addresses one vulnerability in the Apple OSX version, and forty-one vulnerabilities in the Windows version.  For more information, see <a href="http://support.apple.com/kb/HT5766" target="_blank">About the security content of iTunes 11.0.3</a> on Apple&#8217;s support site.</p>
<p>The new version of iTunes is available for download at <a href="http://www.apple.com/itunes/download/" target="_blank">www.apple.com/itunes/download</a>.</p>
<p>As always, ITS recommends that you keep your computers and other devices up to date with the latest security fixes in order to protect your machines and your data from malicious code and unauthorized access.</p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/17/security-updates-for-itunes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday Roundup for May 2013</title>
		<link>http://it-security.usc.edu/2013/05/14/patch-tuesday-roundup-for-may-2013/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=patch-tuesday-roundup-for-may-2013</link>
		<comments>http://it-security.usc.edu/2013/05/14/patch-tuesday-roundup-for-may-2013/#comments</comments>
		<pubDate>Tue, 14 May 2013 23:10:47 +0000</pubDate>
		<dc:creator>mbordas</dc:creator>
				<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[software patches and updates]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=517</guid>
		<description><![CDATA[Today is Patch Tuesday for May 2013. Microsoft released ten security bulletins addressing over thirty vulnerabilities. One critical bulletin addresses a recently discovered &#8220;zero-day&#8221; vulnerability in Internet Explorer 8 and, if you are using that browser, should be installed as &#8230; <a href="http://it-security.usc.edu/2013/05/14/patch-tuesday-roundup-for-may-2013/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Today is Patch Tuesday for May 2013. Microsoft released ten security bulletins addressing over thirty vulnerabilities. One critical bulletin addresses a recently discovered &#8220;zero-day&#8221; vulnerability in Internet Explorer 8 and, if you are using that browser, should be installed as soon as possible. For more information, visit Microsoft&#8217;s <a title="Microsoft Safety and Security Center" href="http://www.microsoft.com/security/default.aspx" target="_blank">Safety &amp; Security Center</a>.</p>
<p>Adobe released updates for Flash Player, Reader, Acrobat, and ColdFusion. For more information, see Adobe&#8217;s <a title="Adobe Security and Advisory Page" href="http://www.adobe.com/support/security/" target="_blank">security bulletin and advisories</a> page.</p>
<p>Mozilla released an update to the Firefox web browser. For more information, or to download the update, see the <a title="Firefox Notes" href="http://www.mozilla.org/en-US/firefox/21.0/releasenotes/" target="_blank">Firefox Notes</a> page.</p>
<p>As always, ITS recommends that you keep your computers and other devices up to date with the latest security fixes in order to protect your machines and your data from malicious code and unauthorized access. For instructions on setting your computer to automatically check for updates, visit the <a title="ITS Security Page" href="http://www.usc.edu/its/security/" target="_blank">ITS Security page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/14/patch-tuesday-roundup-for-may-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-11 #1</title>
		<link>http://it-security.usc.edu/2013/05/11/phish-2013-05-11/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-11</link>
		<comments>http://it-security.usc.edu/2013/05/11/phish-2013-05-11/#comments</comments>
		<pubDate>Sat, 11 May 2013 15:34:00 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=509</guid>
		<description><![CDATA[Many people received multiple copies of the following phish. They came from multiple source email addresses. There are many signs that the message was illegitimate. The senders are non-USC addresses and were most probably compromised accounts since it does not &#8230; <a href="http://it-security.usc.edu/2013/05/11/phish-2013-05-11/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Many people received multiple copies of the following phish. They came from multiple source email addresses.</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-shot-2013-05-11-at-08.08.30.png"><img class="size-full wp-image-511 aligncenter" alt="Screen shot 2013-05-11 at 08.08.30" src="https://it-security.usc.edu/files/2013/05/Screen-shot-2013-05-11-at-08.08.30.png" width="793" height="263" /></a></p>
<p>There are many signs that the message was illegitimate.</p>
<ol>
<li>The senders are non-USC addresses and were most probably compromised accounts since it does not look like they were forged.</li>
<li>The message is not addressed directly to you.  Instead they BCC&#8217;d each recipient and left the To line empty.</li>
<li>Typographical and grammatical mistakes.  &#8220;lick&#8221;?</li>
<li>Non-USC link which was disguised as a supposedly more legitimate looking URL.</li>
<li>What does &#8220;logout the account from your mailbox&#8221; mean?</li>
<li>The odd Copyright 2013.</li>
</ol>
<p>Here is the target web phish form.</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-11-at-08.19.40-.png"><img class="size-full wp-image-510 aligncenter" alt="Screen Shot 2013-05-11 at 08.19.40" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-11-at-08.19.40-.png" width="539" height="569" /></a></p>
<p>There are many signs the form is illegitimate.</p>
<ol>
<li>Not a usc.edu URL.  Though they did try to fool people with the <span style="color: #ff0000">usc</span>.3owl.com.</li>
<li>No USC branding.</li>
<li>None of the links (Change Password? Manage Autoresponder, etc, actually work).</li>
</ol>
<p>Update: looks like this phish has been around since late last year:  <a title="Email Account Phishing: Your Account Is Open in One Other Location" href="http://news.softpedia.com/news/Email-Account-Phishing-Your-Account-Is-Open-in-One-Other-Location-295162.shtml" target="_blank">Email Account Phishing: Your Account Is Open in One Other Location</a></p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/11/phish-2013-05-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-08 #5</title>
		<link>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-08-5</link>
		<comments>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-5/#comments</comments>
		<pubDate>Wed, 08 May 2013 23:53:05 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=503</guid>
		<description><![CDATA[Another over-quota phish.  We do not delete accounts that are over quota.  And they did not even bother to change the text of their phish from their previous victim site, East Tennessee State University.]]></description>
				<content:encoded><![CDATA[<p>Another over-quota phish.  We do not delete accounts that are over quota.  And they did not even bother to change the text of their phish from their previous victim site, East Tennessee State University.</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-4.47.37-PM.png"><img class="alignnone size-full wp-image-504" alt="Screen Shot 2013-05-08 at 4.47.37 PM" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-4.47.37-PM.png" width="510" height="176" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-08 #4</title>
		<link>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-4/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-08-4</link>
		<comments>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-4/#comments</comments>
		<pubDate>Wed, 08 May 2013 23:46:06 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=500</guid>
		<description><![CDATA[Another your-email-will-be-disabled-unless phish. Sent from a compromised account at another institution. The link goes to an obviously unrelated site. Typo in Subject.]]></description>
				<content:encoded><![CDATA[<p>Another your-email-will-be-disabled-unless phish.</p>
<ol>
<li>Sent from a compromised account at another institution.</li>
<li>The link goes to an obviously unrelated site.</li>
<li>Typo in Subject.</li>
</ol>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-4.34.44-PM.png"><img class="alignnone size-full wp-image-501" alt="Screen Shot 2013-05-08 at 4.34.44 PM" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-4.34.44-PM.png" width="781" height="296" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-08 #3</title>
		<link>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-08-3</link>
		<comments>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-3/#comments</comments>
		<pubDate>Wed, 08 May 2013 23:25:16 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[compromised account]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=497</guid>
		<description><![CDATA[Phishers used a compromised faculty account to send Phish 2013-05-08 #1 to other USC addresses.  They managed to send about 100 before we detected and blocked it. Phishers often use this technique because it bypasses blocks of external sites and &#8230; <a href="http://it-security.usc.edu/2013/05/08/phish-2013-05-08-3/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Phishers used a compromised faculty account to send <a title="Phish 2013-05-08 #1" href="https://it-security.usc.edu/2013/05/08/phish-2013-05-08/">Phish 2013-05-08 #1</a> to other USC addresses.  They managed to send about 100 before we detected and blocked it.</p>
<p>Phishers often use this technique because it bypasses blocks of external sites and makes the phish seem more legitimate because it has a USC From address.</p>
<p>The IP used to inject the phish, 199.189.110.30, is registered to Samoa (us3.exchangezone.ws) but seems to be located in Providence or Salt Lake City, Utah.</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-3.57.28-PM.png"><img class="alignnone size-full wp-image-498" alt="Screen Shot 2013-05-08 at 3.57.28 PM" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-3.57.28-PM.png" width="908" height="330" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-08 #2</title>
		<link>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-08-2</link>
		<comments>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-2/#comments</comments>
		<pubDate>Wed, 08 May 2013 19:07:18 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=490</guid>
		<description><![CDATA[Another phish sent to around 100 people this morning.  We were only forwarded the body of the phish so we do not have full headers.  Mail logs show that the claimed sender was MaryJane.Hahner.2@nd.edu. They put some effort into this because &#8230; <a href="http://it-security.usc.edu/2013/05/08/phish-2013-05-08-2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Another phish sent to around 100 people this morning.  We were only forwarded the body of the phish so we do not have full headers.  Mail logs show that the claimed sender was MaryJane.Hahner.2@nd.edu.</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-11.57.37-AM.png"><img class="alignnone size-full wp-image-491 aligncenter" alt="Screen Shot 2013-05-08 at 11.57.37 AM" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-11.57.37-AM.png" width="702" height="167" /></a></p>
<p>They put some effort into this because they used &#8220;ITS Help DESK&#8221;, but why is there a comma?  Plus the usual signs that is a phish:</p>
<ol>
<li>What are &#8220;IP Security upgrades&#8221;?</li>
<li>Grammatical and typographical mistakes.</li>
<li>Non-USC link which was not disguised at all.  We have seen many phish forms hosted at webs.com lately.</li>
<li>The odd Copyright 2013.</li>
</ol>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/08/phish-2013-05-08-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-08 #1</title>
		<link>http://it-security.usc.edu/2013/05/08/phish-2013-05-08/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-08</link>
		<comments>http://it-security.usc.edu/2013/05/08/phish-2013-05-08/#comments</comments>
		<pubDate>Wed, 08 May 2013 17:53:10 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=485</guid>
		<description><![CDATA[Many people received the following phish this morning: There are many signs that the message was illegitimate. The basic premise, used by many phish, is flawed.  Users never need to &#8220;upgrade their email account&#8221;.  email/webmail ugprades occur on the server. &#8230; <a href="http://it-security.usc.edu/2013/05/08/phish-2013-05-08/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Many people received the following phish this morning:</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-9.54.50-AM.png"><img class="size-full wp-image-486 aligncenter" alt="Screen Shot 2013-05-08 at 9.54.50 AM" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-08-at-9.54.50-AM.png" width="687" height="396" /></a></p>
<p>There are many signs that the message was illegitimate.</p>
<ol>
<li>The basic premise, used by many phish, is flawed.  Users never need to &#8220;upgrade their email account&#8221;.  email/webmail ugprades occur on the server.  We would notify customers of the change ahead of time but it is highly unlikely that you would need to do anything.</li>
<li>The sender is a non-USC address and is most probably a compromised account at the other institution (probably fell for a phish).</li>
<li>The message is not addressed directly to you.  Instead they spoofed the recipient as <strong>info@usc.edu</strong>.</li>
<li>The &#8220;HERE&#8221; link goes to a non-USC site but they tried to make it look legitimate with the www.<strong><span style="color: #ff0000">uscedu</span></strong>.byethost24.com.</li>
<li>We store a hash of the password not an encrypted password.</li>
<li>Typographical and grammatical mistakes.</li>
<li>CENTER not CENTRE.  But we do not have a mail support center.</li>
<li>Another oddity present by many phish is the copyright.  Why would this be copyrighted USC Webmail Maintenance Team?</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/08/phish-2013-05-08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>End of Support Date for Windows XP</title>
		<link>http://it-security.usc.edu/2013/05/03/end-of-support-date-for-windows-xp/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=end-of-support-date-for-windows-xp</link>
		<comments>http://it-security.usc.edu/2013/05/03/end-of-support-date-for-windows-xp/#comments</comments>
		<pubDate>Fri, 03 May 2013 19:00:46 +0000</pubDate>
		<dc:creator>mbordas</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[software patches and updates]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=479</guid>
		<description><![CDATA[Microsoft will stop supporting the decade-old Windows XP operating system (OS), now several generations behind the current release, Windows 8, on April 8, 2014. Once support ends, security patches and OS updates will no longer be available for Windows XP. &#8230; <a href="http://it-security.usc.edu/2013/05/03/end-of-support-date-for-windows-xp/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Microsoft will stop supporting the decade-old Windows XP operating system (OS), now several generations behind the current release, Windows 8, on April 8, 2014. Once support ends, security patches and OS updates will no longer be available for Windows XP.</p>
<p>Users with Windows XP should upgrade to a newer operating system before April 2014 in order to continue receiving manufacturer and industry software support, including protection against security vulnerabilities. For more information, see Microsoft&#8217;s <a href="http://www.microsoft.com/en-us/windows/endofsupport.aspx" target="_blank">end of support page</a> for Windows XP.</p>
<p>Older versions of software are generally less secure than newer releases. This is especially true for web browsers. Please take this opportunity to verify that you are using the latest version of your web browser.</p>
<p>The latest versions of the five most popular browsers are:</p>
<ul>
<li>Internet Explorer 10, available at <a href="http://windows.microsoft.com/en-US/internet-explorer/download-ie" target="_blank">windows.microsoft.com/en-US/internet-explorer/download-ie</a> for users of Windows 8, Windows RT, or Windows 7 SP1.</li>
<li>Firefox 20, available at <a href="http://www.mozilla.org/en-US/firefox/new/" target="_blank">www.mozilla.org/en-US/firefox/new</a>.</li>
<li>Chrome 26, available at <a href="https://www.google.com/intl/en/chrome/browser/" target="_blank">www.google.com/intl/en/chrome/browser</a>.</li>
<li>Safari 6, available with Apple&#8217;s OS X from the <a href="http://www.apple.com/osx/apps/app-store.html" target="_blank">Apple App Store</a>.</li>
<li>Opera 12, available at <a href="http://www.opera.com" target="_blank">www.opera.com</a>.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/03/end-of-support-date-for-windows-xp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phish 2013-05-01</title>
		<link>http://it-security.usc.edu/2013/05/01/phish-2013-05-01/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phish-2013-05-01</link>
		<comments>http://it-security.usc.edu/2013/05/01/phish-2013-05-01/#comments</comments>
		<pubDate>Wed, 01 May 2013 17:35:29 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">https://it-security.usc.edu/?p=468</guid>
		<description><![CDATA[Many people received the following phish this morning: There are several signs that it was a phish instead of a legitimate message from JP Morgan Chase. The message came from &#8220;no-reply@bb-lab.com&#8221;. It was not directly addressed to you as a &#8230; <a href="http://it-security.usc.edu/2013/05/01/phish-2013-05-01/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Many people received the following phish this morning:</p>
<p><a href="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-01-10.01.00.png"><img class="alignnone size-full wp-image-469" alt="Screen Shot 2013-05-01 10.01.00" src="https://it-security.usc.edu/files/2013/05/Screen-Shot-2013-05-01-10.01.00.png" width="627" height="411" /></a></p>
<p>There are several signs that it was a phish instead of a legitimate message from JP Morgan Chase.</p>
<ol>
<li>The message came from &#8220;no-reply@bb-lab.com&#8221;.</li>
<li>It was not directly addressed to you as a legitimate warning should be.</li>
<li>Replies are directed to the bogus sender &#8220;no-reply@bb-lab.com&#8221;.</li>
<li>If you hover over the &#8220;Log On to Chase&#8221; link, you will see that the target is actually a site in Romania.</li>
</ol>
<p>We have blocked further similar email as well as the phish web site.  However, if you went to the site before we blocked it and entered any personal information, please change your password immediately.</p>
]]></content:encoded>
			<wfw:commentRss>http://it-security.usc.edu/2013/05/01/phish-2013-05-01/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
