SLIDE 2 An Attack Plan
Target System
Pennstate e-mail system (130,000 users )
Expected Results
Disable communication between administration offices,
- rganizations, professors and students.
Take down or affect some services (psu email, listserv, angel)
How we will do it:
Generate a hit list for the psu domain (xyz123@psu.edu)
“[a-z][a-z0-9] [a-z0-9][0-9]{0,5}@psu.edu” Size:3369.6x106 Time:3 days
filter the list to 130,000 using psu directory search
find a group of zombie machines (with smtp engine) where we can launch the attack from (not hard to find “botnet”)
What will we send:
spam, phishing, attachment with viruses
few hundred messages for each user might take the server down (servers are overloaded)
more fun! malformed spam will also take some clients down (outlook, Eudora,..)
How can we prevent that?