[email protected]
. External researchers or other interested parties should refer to our Responsible Disclosure Policy for more information about reporting vulnerabilities. The [email protected]
email address also forwards to a ZenDesk queue that is monitored by the security team.Users without 2FA enabled that are stale for over 30 days will be blocked/suspended until resolved. This improves the security posture for both the user and
IllumiDesk.
If any systems provide an option to use SMS text as a second factor, this is highly discouraged. Phone company security can be easily subverted by attackers allowing them to take over a phone account. (Ref: 6 Ways Attackers Are Still Bypassing SMS 2-Factor Authentication / 2 minute Youtube social engineering attack with a phone call and crying baby)System Settings
-> Security & Privacy
under the Firewall
tab. It is recommended to select "Block all incoming connections"; however, if choosing not to block all incoming traffic, apply the following configuration (see screenshot):</A>
tag is the text that will be displayed to the user.<a href="http://evilsite.example.org">Google Login!</a>
[email protected]
IllumiDesk.com
as an attachment for it to be investigated. Once you have done so, please proceed to step 2 and report the email as phishing from inside GMail.[email protected]
IllumiDesk.com
phishing
from inside GMail:[email protected]
email address for team members to use in situations that require an immediate security response. Should a team member lose a device such as a thumb drive, mobile phone, tablet, laptop, etc. that contains their credentials or other IllumiDesk-sensitive data they should send an email to [email protected]
right away. When the production and security teams receive an email sent to this address it will be handled immediately. Using this address provides an excellent way to limit the damage caused by a loss of one of these devices.panic
is triggered