Researcher Reveals Widespread Email Data Exposure Vulnerabilities
TL;DR. A security researcher acquired 'noreply' domains, subsequently receiving hundreds of thousands of sensitive corporate and personal emails due to systemic misconfigurations. - Companies mistakenly send private information to 'noreply' addresses, assuming they are unmonitored digital trash cans. - The researcher amassed nearly 402,000 messages since December 2024, exposing injury reports, account credentials, and service orders. - This accidental honeypot highlights significant security flaws, prompting the researcher to alert affected organizations to fix their systems.
- Security researcher Cory Solovewicz purchased 'noreply.us' and 'noreply.net' domains.
- These domains became an 'accidental honeypot', receiving nearly 402,000 unintended emails since December 2024.
- Emails contained sensitive data, including company secrets, personal injury reports, and test platform credentials.
- The issue stems from companies misconfiguring internal systems and treating 'noreply' addresses as unmonitored.
- Solovewicz presented his findings at Defcon and is actively notifying affected entities to rectify their vulnerabilities.
Sources
- A researcher bought noreply.net. Companies started sending him secrets. — arstechnica.com