敏感信息不断流入“不回复”邮箱,而这个人全都看见了。
Sensitive Info Goes into 'No Reply' Emails Constantly. This Guy Sees It All

原始链接: https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/

安全研究员科里·索洛维奇(Cory Solovewicz)因拥有 noreply.us 和 noreply.net 域名,无意中创建了一个巨大的数据“蜜罐”。自购入这些域名以来,他已收到超过 40 万封电子邮件,平均每天约 700 封。这些邮件包含敏感信息,包括伤害报告、披萨订单和企业内部凭据。 这一海量数据源于各机构对其系统的错误配置。企业常在删除账户或使用自动化系统时,将“noreply”(无需回复)地址用作占位符,误以为这些邮件会凭空消失。然而,由于索洛维奇拥有这些域名,这些自动发送的消息全都直接传到了他那里。 索洛维奇在黑客大会(Defcon)上展示了他的发现,并花费时间通知受影响的机构,以鼓励其完善系统审计和安全实践。他强调,幸运的是拥有这些域名的人是他,而不是恶意攻击者。此问题突显了一个反复出现的技术失误:企业倾向于使用公共域名来处理内部流程,而非使用像 *.invalid* 这样保留的非功能性域名。索洛维奇的工作为糟糕的数据管理风险以及正确清理遗留系统配置的重要性敲响了警钟。

Hacker News 新闻 | 往期 | 评论 | 提问 | 展示 | 招聘 | 投稿 登录 “无回复”邮件中频繁泄露敏感信息,他见证了这一切 (wired.com) 8 分,sbulaev 发布于 57 分钟前 | 隐藏 | 往期 | 收藏 | 1 条评论 帮助 mcc1ane 3 分钟前 [–] https://archive.is/xn3gW 回复 考虑申请 YC 2026 年秋季批次!申请通道将于 7 月 27 日关闭。 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699.99 pings per day.

This deluge isn’t the regular flood of spam, newsletters, and unwanted deals that fill many people’s inboxes. Instead, companies and other organizations are inadvertently sending Solovewicz other people’s private information and company secrets. Over the last few years, he’s received injury reports from a city government, confirmation of people’s pizza orders, and account setup emails from a school platform. “I get service orders for people that need repairs. I get lots of test platform credentials,” says Solovewicz, a security researcher and consultant.

Solovewicz is receiving the avalanche of messages as he’s the owner of the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, respectively. After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz tells WIRED. “I had no idea it was going to turn into this.”

Companies may send emails to [companyname]@noreply.net or similar variations believing they aren’t going anywhere, or could not be monitored in any way. Broadly it’s also possible that they may transform a person’s individual email address to send to one of these placeholder style domains if someone leaves a company or deletes their account.

What started out as a personal email project has become a large-scale effort to warn businesses and other groups that they have misconfigured their internal systems and are accidentally sharing sensitive information. Solovewicz, who presented his work at the Defcon security conference yesterday, says ultimately he is relieved that he ended up with the domains rather than criminal hackers or nation states who could use the data maliciously.

“I did not realize that this was going to be as big of a problem as it is,” says Solovewicz, who is not publicly naming impacted entities. The researcher has been alerting affected companies of their problems, encouraging them to fix the errors and misconfigurations. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff.”

Solovewicz says that the noreply.net domain is the largest he owns and has received 400,000 messages over the year and a half that he’s owned it, with 28,365 of those containing attachments. The noreply.us domain has been sent 37,255 messages over 2,345 days since he purchased it in 2020. Over the month before his conference talk, combined, they’ve received more than 11,000 messages. Overall, emails have been sent from more than 14,000 “from” addresses, from 6,200 root domains. The messages are automated by company systems, not written by humans, the researcher says.

While the issue is not a new one—almost 20 years ago, independent security journalist Brian Krebs, then working at the Washington Post, wrote how companies were sending millions of messages to @donotreply.com emails—it is inherently avoidable. For instance, companies could use internal domains or the .invalid domain that is guaranteed not to exist.

Solovewicz is not alone in this voluntary endeavor, which is helping protect the data of companies—often large ones. Earlier this year, Mike Sheward, the head of security at EV charging company Xeal, spent around $15 to buy the domain deleteduser.com. “Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com,” Sheward tells WIRED, pointing out that companies appear to be simply changing email addresses rather than entirely deleting accounts from their systems.

联系我们 contact @ memedata.com