Home / Blogs

Why are *.edu's Compromised so Much?

Terry Zink

When it comes to the problem of outbound spam, one of the experiences that I have, and this was reaffirmed at TechEd, is that the number one source of compromised accounts are educational institutions. That is to say, whenever we have an outbound spam problem and have to hunt down where it is coming from, the highest number of these accounts are phished accounts/credentials from users at an educational institution.

Why is this? Why does so much spam originate from universities? Why don't we see the equivalent in the corporate world?

I don't know the answer. However, I will put forth a couple of theories:

  1. Universities have more lax security regulations. Higher education is stretched for funds and IT administrators just don't have the time to enforce security updates, install A/V software, and/or they allow students to download all sorts of nefarious things (bit torrents, shareware, etc). This software contains keystroke loggers or something similar which steals user credentials and sends them back to the phisher. In other words, lack of security patching combined with users who takes risks is what contributes to the phished account problem.
  2. Universities allow games to run on their computers, and malware targets these games. This is a theory I have and it is similar to (1) above. One of the most commonly occurring worms in the home user world is the Taterf worm which targets user credentials for MMORPGs like World of Warcraft. Taterf spreads via USB thumb drives and misconfigured network mapped drives. Users trade their USB keys and stuff between each other, and this malware grabs user credentials. Since many people use their email addresses as their login information, and passwords as well, phishers inadvertently started collecting email credentials as well. A nice byproduct. But the point is that students are the ones installing all sorts of games and not taking security precautions, resulting in the spread of malware.
  3. Students fall for phishing scams more often. I have no evidence for this, but if students (or possibly staff and faculty) have a higher rate of spamming then that implies that they fall for phishing scams more often. Spam in their inbox that says "Please click on this in order to ensure that you have the latest software" which really installs malware, or steals credentials, is the result of the phish. Students may not have as much experience with computers and then once they hit school, they get one for free. But with new email accounts comes new experiences that they are not familiar with, and hence, they fall for scams.

None of these explanations is really satisfying to me. It's possible that it is a combination of the three of them, and also others that I have not heard of.

By Terry Zink, Program Manager. Visit the blog maintained by Terry Zink here.

Related topics: Malware, Spam, Top-Level Domains

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Hmm.. I'm not so sure about your numbers.. Valdis Kletnieks  –  Jun 16, 2010 10:00 AM PST

You specifically state "That is to say, whenever we have an outbound spam problem and have to hunt down where it is coming from, the greatest number..."

Now let's take a step backwards. You have an *outbound* spam problem. So who's really got the issue here? (Hint - why do you have enough outbound connections using phished .edu credentials that you feel the need to chase down the source?)

OK - let's try running it the other way and assume you were confused about the words "in" and "out", and you're being barraged by *inbound* spam from compromised .edu webmails.  Is it simply because you've already blacklisted large swaths of address space because it's Comcast cablemodem space so direct-to-MX doesn't work, etc, and you only accept mail from a very limited number of sites?

So you get hit with what looks like ".edu's have problems" merely because .edu's have more webmail servers that you're willing to accept mail from. So you block 95% of crap from ISP's out in .com and .net, accept from .edu webmails - and then are surprised that most of what you accept is from .edu's.  That's called "confirmation bias".

Valdis, microsoft hosts email for quite a lot of universities Suresh Ramasubramanian  –  Jun 18, 2010 5:04 PM PST

So I guess when Terry's saying .edu users get phished more than corporate users do, he's got something tlike that in mind when he says "phished .edu users and outbound spam"

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Top Level Domain Holdings Raises $14M for New gTLDs

.ORG COO Discusses Priorities With DailyVista, Pursuit of .NGO Domain

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

The New Domain For Japan, JP.NET, Launches With Exclusive Invitation to Trademark Owners

Being a .PRO When Choosing a Registry Services Partner

Afilias Acquires Registry Services Corporation, .PRO

Thoughts on Applying for a Generic Top-Level Domain

Sedari Launches "Guess the Numbers Game" for New TLD Program

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

.CO Internet Selects Sedo to Broker Previously Unreleased .CO Domain Names

Sedari and NCC Launch Programme to Assist New Registry Operators

.CO Internet Recognized as World Finance 100 Business Leader

2011: A Year in Review, from the Yes2DotAfrica Campaign

Article in the Telegraph Mistakenly Cited Recent Google Investment of $200 Million in dotMobi

Hot Topics

Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign