📜 ⬆️ ⬇️

"Typesquatters" collected 20 GB of someone else's correspondence

Two researchers from Godai Group decided to set up an experiment and check how much private information can be collected if you register domains with typos and pick up mail servers on them. It turned out that this technique is extremely effective. For 30 “fake” domains, 20 GB of letters (about 120,000) were sent to Fortune 500 companies in six months. Approximately 1% of these letters contain confidential information - employee logins and passwords, information on transactions, internal investigations and etc.

120 thousand letters - a good result, given the passivity of the method of collection and absolute secrecy. For six months, no one noticed.

The researchers found that the possibility of registering a domain without a dot exists for 30% of large companies, given their subdomains to which mail is addressed. Some corporations have 60 sub-domains, that is, they are especially vulnerable. If a company has a large flow of letters via internal mail, then some will probably get to the wrong address. For example, on @ seibm.com instead of @ se.ibm.com (IBM's Swedish division) or @ ausintel.com instead of @ aus.intel.com.

In six months, about 120,000 letters were received on 30 domains. Searching for specific keywords gave the following result:
KeywordNumber of letters
Investigation350
Secret425
Unclassified106
Credit card402
Private394
Userid225
Password405
Login495
Confidentiality374
VPN75
Router163
Contract417
Affidavits34
Invoice323
Resume275
It is possible that the collection of someone else's corporate mail in this way is already being done. Researchers have discovered that a number of Taiwanese domains for some of the largest companies are already registered by the Chinese or to suspicious emails. This may well be part of an industrial espionage system.
purposeDomain DoubleOwner's mailing address
adp.comcnadp.comadp@vip.163.com
cisco.comkscisco.comdomainadm@hichina.com
dell.comchndell.comgdguy@163.com
dupont.comsydupont.comsyxxhw@163.com
gm.comucgm.comzydoor@126.com
hp.comchehp.com59031894@qq.com
ibm.comcaibm.com604732486@qq.com
ibm.comseibm.comfjjclaw@263.net
intel.comausintel.comnheras@gmail.com
itt.comcnitt.comdulingqun@sina.com
kohls.comemailkohls.combridgeportltd@gmail.com
manpower.comdemanpower.comtzstudent@163.com
mcd.comcnmcd.com617388068@qq.com
yahoo.comnayahoo.comxxxxxx_vip@yahoo.com.cn
unisys.comcaunisys.comdomainadm@hichina.com
Experiment Results (PDF)

')

Source: https://habr.com/ru/post/128167/


All Articles