敏感信息不断发送至“不回复”邮箱,而这名男子全部截获
Sensitive Information Keeps Going To 'No Reply' Emails, And One Man Gets It All

原始链接: https://www.zerohedge.com/markets/sensitive-information-keeps-going-no-reply-emails-and-one-man-gets-it-all

安全研究员 Cory Solovewicz 和 Mike Sheward 发现了一个重大的隐私漏洞:企业经常将包含敏感信息的自动邮件发送至他们并不拥有的“不回复”(no-reply)或“已删除用户”域名。通过购买这些被遗弃的域名(例如 noreply.net),研究人员无意中拦截了数十万条私人信息。 泄露的数据包括高度敏感的信息,如政府伤情报告、登录凭据、酒店预订信息,甚至工业闭路电视监控录像。研究人员警告称,由于这些域名可公开购买,恶意攻击者(包括犯罪分子或情报机构)完全可以采取同样手段来窃取私人数据。 研究人员已购入 30 多个存在风险的域名以防止被滥用,并通知了受影响的机构。他们强调,这个问题很容易避免;企业不应再假设“不回复”地址是数字死胡同,而应将系统配置为使用内部地址或无法解析的域名。最终,研究人员敦促各机构不要再将这些占位符地址视为无人监管的真空地带,因为它们已经变成了大规模、无意识的数据泄露管道。

相关文章

原文

A couple of security researchers have discovered that one of the internet’s most boring conventions, the fake “no reply” email address, can accidentally become a massive pipeline for private information, according to Wired.

Wired writes that security researcher Cory Solovewicz owns the domains noreply.net and noreply.us. Instead of being digital dead ends, the domains have been flooded with emails that companies apparently assumed nobody would ever receive. Since late 2024, noreply.net alone has collected roughly 400,000 messages, including more than 28,000 with attachments.

And this isn't ordinary spam. Solovewicz has received everything from government injury reports and repair orders to school account information and login credentials. In some cases, companies appear to be sending automated messages to addresses such as [email protected] under the assumption that the messages simply disappear.

“I created an accidental honeypot,” Solovewicz said. What began as a personal email experiment eventually turned into an effort to warn organizations that their own systems were leaking information. He has avoided publicly identifying the affected companies and has been contacting them about the problem.

Another researcher, Mike Sheward, stumbled onto essentially the same problem after spending about $15 on deleteduser.com. Within an hour, emails from three different organizations had already arrived. Since then, messages from at least 100 organizations have landed in domains he controls, including hotel reservations containing customers' names, vacation approval requests, Zoom invitations from a UK government agency and even information about Viagra orders.

One particularly troubling example involved an AI company that monitors industrial workers in the Middle East. Sheward says its systems mistakenly sent him thousands of CCTV images. The obvious concern is that researchers aren't the only people capable of buying these domains. Criminals, extortionists or foreign intelligence services could do exactly the same thing.

The two researchers have now purchased more than 30 domains in an effort to keep them away from malicious actors. Solovewicz also tested more than 7,000 potential placeholder domains and found 328 configured with catch-all inboxes, suggesting the problem could extend far beyond what they've already uncovered.

The frustrating part is that the problem is largely avoidable. Companies can use internal addresses or domains specifically designed not to resolve rather than assuming a random “noreply” or “deleted user” address goes nowhere.

As Solovewicz put it, companies need to stop assuming these domains are unmonitored: “You guys need to fix your systems.”

联系我们 contact @ memedata.com