安全研究员Cory Solovewicz通过拥有noreply.us和noreply.net这两个域名,无意中成为了接收企业错误配置系统发送敏感信息的收件人。[1]自2024年12月以来,这两个域名共收到超过40万封包含客户数据、员工信息和公司机密的邮件。[1]其中noreply.net域名在Solovewicz拥有的1.5年内收到约40万条消息,28,365条包含附件;noreply.us域名自2020年购买以来收到37,255条消息。[1]过去一个月内两个域名合计收到超过11,000条消息。[1]Solovewicz表示:"我没有意识到这会成为这么大的问题。"[1]
邮件来自超过14,000个"from"地址和6,200个根域名,规模之大反映了该问题的普遍性。[1]Solovewicz在Defcon安全会议上公开了这一问题,呼吁企业修复系统配置并停止泄露数据。[1]类似情况并非孤立——安全研究员Mike Sheward花费约15美元购买deleteduser.com域名,同样收到数千封错误配置的邮件。[1]两位研究员已独立购买超过30个域名以防止恶意行为者滥用这类错误配置。[1]Solovewicz扫描了7,136个域名,发现其中328个配置为catch-all收件箱。[1]
Security researcher Cory Solovewicz has inadvertently become a recipient of massive volumes of sensitive corporate data after acquiring the domains noreply.us and noreply.net.[1] Since December 2024, these two domains have collectively received over 400,000 emails containing customer data, employee information, and company secrets sent by thousands of organizations with misconfigured mail systems.[1] The noreply.net domain alone has received approximately 400,000 messages in the 1.5 years since Solovewicz obtained it, with 28,365 of those containing attachments, while noreply.us has accumulated 37,255 messages since its purchase in 2020.[1] In just the past month, the two domains received more than 11,000 messages combined, originating from over 14,000 different "from" addresses across 6,200 root domains.[1]
Solovewicz revealed the scope of the problem at the Defcon security conference, stating: "I did not realize that this was going to be as big of a problem as it is."[1] Fellow security researcher Mike Sheward independently discovered a similar vulnerability after spending approximately $15 to register the deleteduser.com domain, which similarly began receiving thousands of misconfigured emails.[1] To prevent malicious actors from exploiting this gap, the two researchers have jointly purchased over 30 domains to act as catch-alls.[1] Solovewicz scanned 7,136 domains and identified 328 configured as catch-all inboxes, underscoring how widespread this configuration flaw has become across the internet.[1]