Select Page


A couple of security researchers have discovered that one of the internet’s most boring conventions, the fake “no reply” email address, can accidentally become a massive pipeline for private information, according to Wired.

Wired writes that security researcher Cory Solovewicz owns the domains noreply.net and noreply.us. Instead of being digital dead ends, the domains have been flooded with emails that companies apparently assumed nobody would ever receive. Since late 2024, noreply.net alone has collected roughly 400,000 messages, including more than 28,000 with attachments.

And this isn’t ordinary spam. Solovewicz has received everything from government injury reports and repair orders to school account information and login credentials. In some cases, companies appear to be sending automated messages to addresses such as companyname@noreply.net under the assumption that the messages simply disappear.

“I created an accidental honeypot,” Solovewicz said. What began as a personal email experiment eventually turned into an effort to warn organizations that their own systems were leaking information. He has avoided publicly identifying the affected companies and has been contacting them about the problem.

Another researcher, Mike Sheward, stumbled onto essentially the same problem after spending about $15 on deleteduser.com. Within an hour, emails from three different organizations had already arrived. Since then, messages from at least 100 organizations have landed in domains he controls, including hotel reservations containing customers’ names, vacation approval requests, Zoom invitations from a UK government agency and even information about Viagra orders.

One particularly troubling example involved an AI company that monitors industrial workers in the Middle East. Sheward says its systems mistakenly sent him thousands of CCTV images. The obvious concern is that researchers aren’t the only people capable of buying these domains. Criminals, extortionists or foreign intelligence services could do exactly the same thing.

The two researchers have now purchased more than 30 domains in an effort to keep them away from malicious actors. Solovewicz also tested more than 7,000 potential placeholder domains and found 328 configured with catch-all inboxes, suggesting the problem could extend far beyond what they’ve already uncovered.

The frustrating part is that the problem is largely avoidable. Companies can use internal addresses or domains specifically designed not to resolve rather than assuming a random “noreply” or “deleted user” address goes nowhere.

As Solovewicz put it, companies need to stop assuming these domains are unmonitored: “You guys need to fix your systems.”



Source link

Visited 1 times, 1 visit(s) today
GLA NEWS