Source: Ars TechnicaView original ↗
Copyright remains with the original source. This site only collects, translates, or reformats the material.
Media: 0 verified, 1 source-only
What happened
Analysis and impact
根据 Ars Technica 的报道,研究人员在购买该域名并设置了一个全收(catch-all)邮箱后,很快便开始接收到大量本应发往各公司内部系统的邮件。这些邮件并非垃圾信息,而是实实在在的业务通信,内容涉及重置密码链接、客户支持工单、机密商业文件以及内部系统通知。问题的根源在于,许多企业在发送自动通知或内部抄送时,习惯使用 noreply@其公司域名.com 这类地址,但员工或系统在手动输入时,时常会错误地将其拼写为 @noreply.net 这样的公共域名。
由于 noreply.net 并非任何企业的专属资产,当它被个人控制后,所有因拼写错误而误发至此的邮件便直接落入了该域名所有者的收件箱。原文指出,这种错误配置相当于将内部机密信息直接投递到了一个公共数字邮箱,攻击者甚至无需进行复杂的网络入侵,仅凭域名解析就能持续收割敏感数据。该研究揭示了一个长期被忽视的供应链安全问题:企业对外部依赖的假设存在盲区,默认某些域名是无人控制的“死地址”,却未意识到它们可以被任何人注册并用于接收信息。
这一发现为信息安全领域敲响了警钟,它表明除了防范外部攻击,机构还需审查其通信流程中对第三方域名的隐性信任。原文未提供受影响公司的具体名单,但强调此类问题可能广泛存在于各类规模的企业中。对于企业而言,除了加强员工培训以避免输入错误外,更根本的解决方案是严格验证所有外发邮件的收件人域名归属,或是在内部系统中彻底弃用可能产生歧义的公共域名后缀。
References
Original source text
Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699.99 pings per day.
This deluge isn’t the regular flood of spam, newsletters, and unwanted deals that fill many people’s inboxes. Instead, companies and other organizations are inadvertently sending Solovewicz other people’s private information and company secrets. Over the last few years, he’s received injury reports from a city government, confirmation of people’s pizza orders, and account setup emails from a school platform. “I get service orders for people that need repairs. I get lots of test platform credentials,” says Solovewicz, a security researcher and consultant.
Solovewicz is receiving the avalanche of messages as he’s the owner of the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, respectively. After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz tells WIRED. “I had no idea it was going to turn into this.”