A researcher bought noreply.net. Companies started sending him secrets
摘要
安全研究员 Solovewicz 购买了 noreply.net 和 noreply.us 域名,一年多来收到约 40 万封邮件,其中 28,365 封带附件;noreply.us 自 2020 年购买以来收到 37,255 封。邮件来自 14,000 多个发件地址、6,200 个根域名,均为公司系统自动发送。他已在提醒受影响公司修复配置。另一名安全人员 Mike Sheward 花约 15 美元购买 deleteduser.com,一小时内就有三家机构向其发送邮件,已收到来自至少 100 家机构的数千封意外邮件,内容涉及药品订单、休假审批、酒店预订和会议邀请等。文章指出此问题近 20 年前就曾被报道,并提到公司可使用内部域名或 .invalid 域名来避免。
荐读理由
买下 noreply.net 这类域名就能持续收到企业误发的机密邮件,这提醒你排查自己产品里硬编码的 noreply 发件地址,避免把用户数据泄露给陌生人
原文
“I did not realize that this was going to be as big of a problem as it is,” says Solovewicz, who is not publicly naming impacted entities. The researcher has been alerting affected companies of their problems, encouraging them to fix the errors and misconfigurations. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff.”
Solovewicz says that the noreply.net domain is the largest he owns and has received 400,000 messages over the year and a half that he’s owned it, with 28,365 of those containing attachments. The noreply.us domain has been sent 37,255 messages over 2,345 days since he purchased it in 2020. Over the month before his conference talk, combined, they’ve received more than 11,000 messages. Overall, emails have been sent from more than 14,000 “from” addresses, from 6,200 root domains. The messages are automated by company systems, not written by humans, the researcher says.
While the issue is not a new one—almost 20 years ago, independent security journalist Brian Krebs, then working at the Washington Post, wrote how companies were sending millions of messages to @donotreply.com emails—it is inherently avoidable. For instance, companies could use internal domains or the .invalid domain that is guaranteed not to exist.
Solovewicz is not alone in this voluntary endeavor, which is helping protect the data of companies—often large ones. Earlier this year, Mike Sheward, the head of security at EV charging company Xeal, spent around $15 to buy the domain deleteduser.com. “Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com,” Sheward tells WIRED, pointing out that companies appear to be simply changing email addresses rather than entirely deleting accounts from their systems.
Like Solovewicz, Sheward has seen thousands of unintended emails coming his way—from at least 100 different organizations—across multiple domains he now owns. He’s had emails detailing people’s Viagra orders, messages asking him to approve people’s work vacations or leaves of absence, hotel bookings including people’s full names, and invitations to Zoom meetings from a UK government agency. “There’s a lot of cybersecurity companies and a few Microsoft partner companies as well,” Sheward says. A couple of weeks ago he got an invitation to one San Francisco company’s summer BBQ, addressed to “Dear Deleted User.”
这条对你有帮助吗?