A researcher bought noreply.net. Companies started sending him secrets.

A researcher bought noreply.net. Companies started sending him secrets.

一位研究人员买下了 noreply.net,结果公司开始向他发送机密信息。

Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699.99 pings per day. Cory Solovewicz 收到的垃圾邮件比你多得多。说真的,多得惊人。自 2024 年 12 月以来,这位安全研究人员所持有的域名之一已经接收了 401,796 封邮件——据他计算,平均每天有 699.99 次请求。

This deluge isn’t the regular flood of spam, newsletters, and unwanted deals that fill many people’s inboxes. Instead, companies and other organizations are inadvertently sending Solovewicz other people’s private information and company secrets. Over the last few years, he’s received injury reports from a city government, confirmation of people’s pizza orders, and account setup emails from a school platform. 这股洪流并非填满许多人收件箱的常规垃圾邮件、时事通讯或促销广告。相反,各公司和其他组织正在无意中将他人的私人信息和公司机密发送给 Solovewicz。在过去几年里,他收到过市政府的伤害报告、人们的披萨订单确认信息,以及来自学校平台的账户设置邮件。

“I get service orders for people that need repairs. I get lots of test platform credentials,” says Solovewicz, a security researcher and consultant. Solovewicz is receiving the avalanche of messages as he’s the owner of the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, respectively. “我收到了需要维修的人的服务订单,还收到了大量的测试平台凭据,”身为安全研究员和顾问的 Solovewicz 说道。Solovewicz 之所以收到如雪片般飞来的邮件,是因为他分别于 2020 年和 2024 年买下了 noreply.us 和 noreply.net 这两个域名。

After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz tells WIRED. “I had no idea it was going to turn into this.” 这位研究人员最初计划将 noreply.us 域名用作“全收”(catch-all)邮箱(即接收发送到该域名下任何 @ 地址的邮件),以过滤信息并增强隐私保护,但他很快发现其他系统正在向 @noreply.us 地址发送邮件。“我意外地创建了一个蜜罐,”Solovewicz 告诉《连线》(WIRED)杂志,“我根本没想到会变成这样。”

Companies may send emails to [companyname]@noreply.net or similar variations believing they aren’t going anywhere, or could not be monitored in any way. Broadly it’s also possible that they may transform a person’s individual email address to send to one of these placeholder style domains if someone leaves a company or deletes their account. 公司可能会向 [公司名]@noreply.net 或类似的变体发送邮件,认为这些邮件不会到达任何地方,或者无法被任何人监控。更广泛地说,如果有人离职或删除了账户,公司也可能将个人的电子邮件地址转换为这些占位符式的域名。

What started out as a personal email project has become a large-scale effort to warn businesses and other groups that they have misconfigured their internal systems and are accidentally sharing sensitive information. Solovewicz, who presented his work at the Defcon security conference yesterday, says ultimately he is relieved that he ended up with the domains rather than criminal hackers or nation states who could use the data maliciously. 最初的一个个人电子邮件项目,现在已经演变成一项大规模行动,旨在警告企业和其他组织:他们的内部系统配置错误,正在无意中泄露敏感信息。昨天在 Defcon 安全会议上展示其研究成果的 Solovewicz 表示,他最终感到庆幸的是,这些域名落在了他手里,而不是落入可能恶意利用这些数据的犯罪黑客或国家行为体手中。

“I did not realize that this was going to be as big of a problem as it is,” says Solovewicz, who is not publicly naming impacted entities. The researcher has been alerting affected companies of their problems, encouraging them to fix the errors and misconfigurations. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff.” “我没意识到这个问题竟然如此严重,”Solovewicz 说道,他并未公开受影响实体的名称。这位研究人员一直在提醒受影响的公司,鼓励他们修复错误和配置问题。“我只是希望公司和组织能做正确的事,审计他们的系统并修复这些问题。”

Solovewicz says that the noreply.net domain is the largest he owns and has received 400,000 messages over the year and a half that he’s owned it, with 28,365 of those containing attachments. The noreply.us domain has been sent 37,255 messages over 2,345 days since he purchased it in 2020. Over the month before his conference talk, combined, they’ve received more than 11,000 messages. Overall, emails have been sent from more than 14,000 “from” addresses, from 6,200 root domains. The messages are automated by company systems, not written by humans, the researcher says. Solovewicz 表示,noreply.net 是他拥有的最大的域名,在他持有的这一年半里,它接收了 40 万封邮件,其中 28,365 封包含附件。自 2020 年购买以来,noreply.us 域名在 2,345 天内收到了 37,255 封邮件。在他参加会议演讲前的一个月里,这两个域名总共收到了超过 11,000 封邮件。总体而言,这些邮件来自 6,200 个根域名的 14,000 多个“发件人”地址。研究人员指出,这些邮件是由公司系统自动发送的,而非人工撰写。

While the issue is not a new one—almost 20 years ago, independent security journalist Brian Krebs, then working at the Washington Post, wrote how companies were sending millions of messages to @donotreply.com emails—it is inherently avoidable. For instance, companies could use internal domains or the .invalid domain that is guaranteed not to exist. 虽然这个问题并不新鲜——近 20 年前,当时在《华盛顿邮报》工作的独立安全记者 Brian Krebs 就曾撰文指出,公司是如何向 @donotreply.com 邮箱发送数百万封邮件的——但它本质上是可以避免的。例如,公司可以使用内部域名或保证不存在的 .invalid 域名。

Solovewicz is not alone in this voluntary endeavor, which is helping protect the data of companies—often large ones. Earlier this year, Mike Sheward, the head of security at EV charging company Xeal, spent around $15 to buy the domain deleteduser.com. “Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com,” Sheward tells WIRED, pointing out that companies appear to be simply changing email addresses rather than entirely deleting accounts from their systems. Solovewicz 在这项自愿行动中并不孤单,他的工作有助于保护公司(通常是大型公司)的数据。今年早些时候,电动汽车充电公司 Xeal 的安全主管 Mike Sheward 花了大约 15 美元买下了 deleteduser.com 域名。“在第一个小时内,就有三个不同的组织向 @deleteduser.com 发送了邮件,”Sheward 告诉《连线》,他指出公司似乎只是在更改电子邮件地址,而不是从系统中彻底删除账户。

Like Solovewicz, Sheward has seen thousands of unintended emails coming his way—from at least 100 different organizations—across multiple domains he now owns. He’s had emails detailing people’s Viagra orders, messages asking him to approve people’s work vacations or leaves of absence, hotel bookings including people’s full names, and invitations to Zoom meetings from a UK government agency. 和 Solovewicz 一样,Sheward 在他现在拥有的多个域名中,也收到了来自至少 100 个不同组织的数千封意外邮件。他收到过详细说明人们伟哥订单的邮件、请求他批准员工休假或请假的邮件、包含人们全名的酒店预订信息,以及来自英国政府机构的 Zoom 会议邀请。

“There’s a lot of cybersecurity companies and a few Microsoft partner companies as well,” Sheward says. A couple of weeks ago he got an invitation to one San Francisco company’s summer BBQ, addressed to “Dear Deleted User.” One of the most frequent sources of email, Sheward says without naming the firm, is an AI company that uses object recognition technology to detect workers at industrial sites in the Middle East who may not be following safety protocols. The researcher has received thousands of CCTV stills from the firm, he says. “其中有很多网络安全公司,还有几家微软的合作伙伴公司,”Sheward 说。几周前,他收到了一家旧金山公司的夏季烧烤邀请,收件人写着“亲爱的已删除用户”。Sheward 在不透露公司名称的情况下表示,最频繁的邮件来源之一是一家人工智能公司,该公司使用物体识别技术来检测中东工业现场的工人是否遵守安全规程。这位研究人员说,他已经从该公司收到了数千张闭路电视监控截图。

“I am being a good guardian of the Internet dumpster—but if I had been a bad one, it’s not hard to see how this information that is willingly thrown at my face could be misused,” he wrote in a Medium post in April. As both Solovewicz and Sheward realized the potential scale of the misplaced emails—and what a goldmine the data would be for hackers and extortionists—they, working independently, have purchased more than 30 domains to try and limit the potential for malicious actors to copy the approach. “我正在做一个互联网垃圾堆的守护者——但如果我是一个坏人,不难看出这些被主动送到我面前的信息会如何被滥用,”他在四月份的一篇 Medium 文章中写道。随着 Solovewicz 和 Sheward 都意识到这些错发邮件的潜在规模,以及这些数据对黑客和勒索者来说是多么大的金矿,他们独立行动,购买了 30 多个域名,试图限制恶意行为者复制这种做法的可能性。

As part of his Defcon talk, Solovewicz explained he has been building a probe to test if other possible placeholder domains may be configured to receive email. “I’ve scanned 7,136 domains, and 328 of them were identified as having catch-all inboxes configured,” Solovewicz says. “I’m not sure I can say how large of a problem this is, but my concern is that what I ‘accidentally’ found when I registered my domain is just the tip of the…” 作为 Defcon 演讲的一部分,Solovewicz 解释说他一直在构建一个探测器,以测试其他可能的占位符域名是否被配置为接收电子邮件。“我已经扫描了 7,136 个域名,其中 328 个被确定配置了全收收件箱,”Solovewicz 说。“我不确定我能说这个问题有多大,但我担心的是,我在注册域名时‘偶然’发现的情况只是冰山一角……”