Tom's Lemmy
  • Communities
  • Support Lemmy
  • Search
  • Login
Sysadmin@lemmy.worldbywewbull@feddit.uk
2 months

Dangers of placeholder domains

infosec.exchange English

Great example of why using placeholders like xxx@deleteduser.com is a bad idea.

6
    Mike Sheward (@[email protected])
    infosec.exchange
    i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with [email protected] or similar. The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email. And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D #infosec
    You must log in or register to comment.
    • slazer2au@lemmy.worldEnglish
      2 months

      Apart from example.com are their any documentation only domains?

      Credit cards have test numbers, IP addresses have TEST-NET1,2,and 3 for ipv4 and 2001:db8:: for V6.

        • frongt@lemmy.zip
          2 months

          https://www.iana.org/assignments/special-use-domain-names/special-use-domain-names.xhtml

            • slazer2au@lemmy.worldEnglish
              2 months

              .onion or arpa are good ones.

            • SkaveRat@discuss.tchncs.de
              2 months

              example.net and example.org

            • hactar42@lemmy.world
              2 months

              That’s why I stick with contoso and fabrikam.

              • einkorn@feddit.org
                2 months

                There was a talk at 39C3 about abandoned (German) government domains (scroll down for an English audio track).

                Sysadmin@lemmy.world

                sysadmin@lemmy.world
                <p>A community dedicated to the profession of IT Systems Administration</p> <p>No generic Lemmy issue posts please! Posts about Lemmy belong in one o

                Subscribe from Remote Instance

                Create a post
                You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

                A community dedicated to the profession of IT Systems Administration

                No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
                [email protected]
                [email protected]
                [email protected]
                [email protected]

                Visibility: Public

                This community is visible to everyone.

                • 10 users / Day
                • 215 users / Week
                • 224 users / Month
                • 1.37K users / 6 months
                • 1 local subscriber
                • 14.5K subscribers
                • 183 Posts
                • 1.26K Comments
                • Modlog
                • UI: 1.0.0-alpha.12
                • BE: 1.0.0-alpha.15
                • Modlog
                • Instances
                • Docs
                • Code
                • join-lemmy.org