Skip to content
  • Kategorien
  • Aktuell
  • Tags
  • Beliebt
  • World
  • Benutzer
  • Gruppen
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Standard: (Kein Skin)
  • Kein Skin
Einklappen

other.li Forum

  1. Übersicht
  2. Uncategorized
  3. i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser...

i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser...

Geplant Angeheftet Gesperrt Verschoben Uncategorized
infosec
50 Beiträge 33 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • ? Gast

    @petabites @SecureOwl

    the number of things network solutions tech support can't figure out would fill a book... 😉

    ? Offline
    ? Offline
    Gast
    schrieb zuletzt editiert von
    #29

    @paul_ipv6

    early on with them (my 4 character assigned NIC handle) the NetSol tech guys were ex-NSA iirc, lol

    ? 1 Antwort Letzte Antwort
    0
    • ? Gast

      @paul_ipv6

      early on with them (my 4 character assigned NIC handle) the NetSol tech guys were ex-NSA iirc, lol

      ? Offline
      ? Offline
      Gast
      schrieb zuletzt editiert von
      #30

      @petabites

      i worked for an ISP that was bidding against NetSol for the registry/registrar stuff. 😉

      1 Antwort Letzte Antwort
      0
      • ? Gast

        i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

        The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

        And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

        #infosec

        ? Offline
        ? Offline
        Gast
        schrieb zuletzt editiert von
        #31

        @SecureOwl lol

        1 Antwort Letzte Antwort
        0
        • ? Gast

          i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

          The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

          And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

          #infosec

          ? Offline
          ? Offline
          Gast
          schrieb zuletzt editiert von
          #32

          wow it looks like a major hospitality management platform in europe does this because i just started to get lists of folks and which hotels they are checking in to

          good lord people

          ? 1 Antwort Letzte Antwort
          0
          • ? Gast

            wow it looks like a major hospitality management platform in europe does this because i just started to get lists of folks and which hotels they are checking in to

            good lord people

            ? Offline
            ? Offline
            Gast
            schrieb zuletzt editiert von
            #33

            i feel an email to the information commissioners office coming on

            ? 1 Antwort Letzte Antwort
            0
            • ? Gast

              @SecureOwl Considering they can't just use null, what could be an acceptable option? @invalid? Although, to be fair, if they can't just null is because something is validating email, so it might require a TLD. Nah... I guess there is no way to rationalize this.

              ? Offline
              ? Offline
              Gast
              schrieb zuletzt editiert von
              #34

              @qgustavor @SecureOwl One of the domains reserved for testing (effectively) like example.com would do it

              1 Antwort Letzte Antwort
              0
              • ? Gast

                i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                #infosec

                ? Offline
                ? Offline
                Gast
                schrieb zuletzt editiert von
                #35

                @SecureOwl
                What a strange thing for people to do. They could change the email deleted@local or maybe actually delete the data.

                ? 1 Antwort Letzte Antwort
                0
                • ? Gast

                  i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                  The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                  And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                  #infosec

                  ? Offline
                  ? Offline
                  Gast
                  schrieb zuletzt editiert von
                  #36

                  @SecureOwl the main reason I don't do well as a pentester is that I never try a lot of things simply because I think "nah, nobody would be that stupid". And then reality proves I am waaaaaaay too optimistic.

                  ? 1 Antwort Letzte Antwort
                  0
                  • ? Gast

                    i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                    The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                    And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                    #infosec

                    ? Offline
                    ? Offline
                    Gast
                    schrieb zuletzt editiert von
                    #37

                    @SecureOwl “””””deleted”””””

                    1 Antwort Letzte Antwort
                    0
                    • ? Gast

                      @SecureOwl we have a top level domain for this at home: .invalid

                      ? Offline
                      ? Offline
                      Gast
                      schrieb zuletzt editiert von
                      #38

                      @SecureOwl at the very least use deleteduser.the-actual-company-domain.whatever instead of a completely foreign domain name anyone can buy

                      1 Antwort Letzte Antwort
                      0
                      • ? Gast

                        @paul_ipv6 @SecureOwl lord only knows what example.com receives

                        ? Offline
                        ? Offline
                        Gast
                        schrieb zuletzt editiert von
                        #39

                        @cw @paul_ipv6 @SecureOwl to train a markov bot on whatever gets mailed to there would be hillarious but probably not a very good idea

                        1 Antwort Letzte Antwort
                        0
                        • ? Gast

                          i feel an email to the information commissioners office coming on

                          ? Offline
                          ? Offline
                          Gast
                          schrieb zuletzt editiert von
                          #40

                          @SecureOwl I second that 😬

                          1 Antwort Letzte Antwort
                          0
                          • ? Gast

                            @SecureOwl
                            What a strange thing for people to do. They could change the email deleted@local or maybe actually delete the data.

                            ? Offline
                            ? Offline
                            Gast
                            schrieb zuletzt editiert von
                            #41

                            @xinit @SecureOwl or something under .invalid at least

                            though if they know about that they probably know to actually erase the data

                            also i think deleted@invalid is a valid email (since you can just use an apex domain if you have one lying around but almost nobody does) but i reckon a lot of validation regexes reject it

                            1 Antwort Letzte Antwort
                            0
                            • ? Gast

                              i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                              The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                              And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                              #infosec

                              ? Offline
                              ? Offline
                              Gast
                              schrieb zuletzt editiert von
                              #42

                              @SecureOwl if you wanted you could turn that domain into the next “have I been pwned”, but “have I been not actually deleted”

                              1 Antwort Letzte Antwort
                              0
                              • ? Gast

                                i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                                The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                                And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                                #infosec

                                ? Offline
                                ? Offline
                                Gast
                                schrieb zuletzt editiert von
                                #43

                                @SecureOwl What about userdeleted?

                                1 Antwort Letzte Antwort
                                0
                                • ? Gast

                                  @briankrebs @SecureOwl @chetfaliszek oh yesh, I remember that one.

                                  Needless to say I think #DoNotReply-Addresses should be outlawed and using one should get a domain banned until the operators apologize personally…

                                  ? Offline
                                  ? Offline
                                  Gast
                                  schrieb zuletzt editiert von
                                  #44

                                  @kkarhan @briankrebs @SecureOwl @chetfaliszek i think they're fine for automated notifications esp if a reply-to header is given

                                  1 Antwort Letzte Antwort
                                  0
                                  • ? Gast

                                    @SecureOwl the main reason I don't do well as a pentester is that I never try a lot of things simply because I think "nah, nobody would be that stupid". And then reality proves I am waaaaaaay too optimistic.

                                    ? Offline
                                    ? Offline
                                    Gast
                                    schrieb zuletzt editiert von
                                    #45

                                    @womble @SecureOwl Sigh, AFAIK the reality is it is extremely difficult if not impossible to brainstorm the lowest (highest?) level of stupid that will occur in the wild. People tend to apply very simple & limited set of responses to everything in their life, and when operating out of their core familiar domains very few will stop to ponder if what works in the dessert might not work in the ocean.

                                    1 Antwort Letzte Antwort
                                    0
                                    • ? Gast

                                      i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                                      The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                                      And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                                      #infosec

                                      ? Offline
                                      ? Offline
                                      Gast
                                      schrieb zuletzt editiert von
                                      #46

                                      Up to about 24 different orgs now, overnight had some emails containing PII of 'deleted' users from a:

                                      UAE based Gym Chain
                                      South African HR Platform
                                      EU based Hotel Reservations Platform
                                      India based Delivery Service

                                      and best of all

                                      US based Antivirus Manufacturer and Cybersecurity Provider

                                      ? dannotdaniel@hellions.cloudD 2 Antworten Letzte Antwort
                                      0
                                      • ? Gast

                                        Up to about 24 different orgs now, overnight had some emails containing PII of 'deleted' users from a:

                                        UAE based Gym Chain
                                        South African HR Platform
                                        EU based Hotel Reservations Platform
                                        India based Delivery Service

                                        and best of all

                                        US based Antivirus Manufacturer and Cybersecurity Provider

                                        ? Offline
                                        ? Offline
                                        Gast
                                        schrieb zuletzt editiert von
                                        #47

                                        And of course the hotel reservations platform is happily spitting out the name of guests and their contact info to the Deleted User email address

                                        1 Antwort Letzte Antwort
                                        0
                                        • ? Gast

                                          i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                                          The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                                          And yes, all of those emails contain the actual PII of the person who has been 'deleted' 😄

                                          #infosec

                                          ? Offline
                                          ? Offline
                                          Gast
                                          schrieb zuletzt editiert von
                                          #48

                                          @SecureOwl HA!

                                          GDPR is a joke. Over under on how many of these companies face repercussions?

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen


                                          • Anmelden

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Kategorien
                                          • Aktuell
                                          • Tags
                                          • Beliebt
                                          • World
                                          • Benutzer
                                          • Gruppen