Security and your Webserve account
Colleagues
No action is required on your part at this time, but we write to remind you of two essential ingredients to the security of your Webserve account.
1. No one at IU (including UITS) will ever ask for your passphrase for any reason . in person or via phone, chat, or email . nor should you provide it when requesting assistance from us. If you doubt the authenticity of an email or web site, or worry about your IT accounts, contact the Support Center as soon as possible:
- Email: ithelp@iu.edu
- Live chat: http://ithelplive.iu.edu
- Phone (24/7): IU Bloomington (812) 855-6789; IUPUI (317) 274-4357
2. Maintaining a stable secure Web presence is a team effort. As the stakeholder for your Webserve account, it.s your responsibility to stay informed about updates and security issues surrounding any third-party software you install in your account such as Joomla or WordPress. Always use the most current, patched version to ensure the stability of the host and avoid degradation of services or create problems for other sites on Webserve. You should also always use strong passwords associated with any software you install.
Several Webserve accounts have been compromised in recent weeks as a result of flaws in older versions of software, particularly WordPress, which have been installed locally in user accounts. On a shared environment such as Webserve, once one account is compromised, other accounts will be targeted by the perpetrator as he or she scans for vulnerabilities to exploit.
Please read through Guidelines for Installing Software on IU Central Web Account at: http://webmaster.iu.edu/tool_guide_info/user_software_guidelines.shtml
The University Information Security Office is also available to provide free web application scans upon request. These scans can provide you with a report to mitigate any security concerns. For detail and to request a scan, see Web Application Vulnerability Scanner at: http://protect.iu.edu/tools/web-scanner
Thank you,
IU Webmaster Services
http://webmaster.iu.edu
wmhelp@iu.edu



