Results 1 to 3 of 3
Like Tree4Likes
  • 3 Post By INDRANIL
  • 1 Post By Student26

Thread: Missing dots from email addresses opens 20GB data leak !!!

  1. #1
    The Specialist *
    Overall activity: 36.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,433
    Liked
    900 times
    Points
    51,197

    Angry Missing dots from email addresses opens 20GB data leak !!!

    Security researchers have captured 120,000 emails intended for Fortune 500 companies by exploiting a basic typo. The emails included trade secrets, business invoices, personal information about employees, network diagrams and passwords.

    Researchers Peter Kim and Garrett Gee did this by buying 30 internet domains they thought people would send emails to by accident (a practice known as typosquatting).

    The domain names they chose were all identical to subdomains used by Fortune 500 companies save for a missing dot.

    Having purchased the domains they simply sat back and watched as users mistakenly sent them over 120,000 emails in six months.

    Kim and Garrett have not identified their targets but have revealed that they were chosen from a list of 151 Fortune 500 companies they regarded as vulnerable to their variation of typosquatting. The list is jam-packed with household names like Dell, Microsoft, Halliburton, PepsiCo and Nike.

    The emails they collected included some worryingly sensitive corporate information, including:

    Passwords for an IT firm's external Cisco routers
    Precise details of the contents of a large oil company's oil tankers
    VPN details and passwords for a system managing road tollways

    The researchers also warn of how easy it would have been to turn their passive typosquatting into an even more dangerous man-in-the-middle attack. Such an attack would have allowed them to capture entire email conversations rather than just individual stray emails.

    To perform a man-in-the-middle attack an attacker would simply forward copies of any emails they receive to the addresses they were supposed to go to in the first place. The forwarded emails would be modified to contain a bogus return addresses owned by the attacker.

    By forwarding and modifying emails in this way the attacker establishes themselves as a silent rely between all the individuals in the conversation.



    Typosquatting isn't new so it's striking that the researchers managed to capture so much information by focusing on just one common mistake. They captured 20GB of data in six months using only basic technical skills and 30 domains costing no more than a few dollars each.

    A determined attacker with a modest budget could easily afford to buy domains covering a vast range of organisations and typos.
    So always pay attention when sending mail to some or opening an attachment . Stay safe & have a nice time .


    More & Source
    .
    I don't need to know everything, I just need to know where to find it, when I need it.

  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Jul 2010
    Location
    England
    Posts
    860
    Liked
    182 times
    Points
    8,891
    And these are companies run by smart people :P

    Well teh best of use make mistakes, who hasn't.
    “Nature uses as little as possible of anything.”
    - Johannes Kepler

  3. #3
    The Specialist *
    Overall activity: 36.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,433
    Liked
    900 times
    Points
    51,197
    Yes I doubt how much smart they are . Regards.

 

 

Similar Threads

  1. Replies: 4
  2. Replies: 8
  3. .Dll Opens With Notepad
    By Vibhanshu in forum Software
    Replies: 3
  4. Many dots on the screen?
    By luffy in forum General Forum
    Replies: 10
  5. Get more live email addresses
    By bahirzaheri8 in forum General Forum
    Replies: 1

Tags for this Thread

All times are GMT +8. The time now is 09:23 PM.