Hacking law firms with abandoned domain names
medium.com
medium.com
I have dealt with firms that pay tens of thousands per month in physical space rental that will balk at the idea of a couple-few thousand per year for IT/web infrastructure/maintenance/etc.
Lawyers are probably not especially more cheapskate than other people, but I would not exactly be surprised if we are.
Let's say your name is Jon Doe and you've purchased domain.tld that was previously-used by some company. So you create to yourself jon@domain.tld, and figure out that the previous owner had an employee named Jon that used it as a primary or secondary email across dozens of most popular services.
How the hell do you proceed with your account creation?
The entirety of the web is built on the notion that email addresses are unique, but there are multiple cases in which that might not be the case. What are your options then? jon2@domain.tld?
jon+servicename@domain.ltd
If the service will accept that of course. It's perfectly valid, and you'll know if it works when you get the confirmation email. Without quotes, local-parts may consist of any
combination of alphabetic characters, digits, or any of
the special characters
! # $ % & ' * + - / = ? ^ _ ` . { | } ~
https://tools.ietf.org/html/rfc3696#page-5But the point the GP was making is that email addresses are treated by services as if the will always be tied to the same person, but that's simply not true.
An interesting related technique is known as bit-squatting where you register domain names of a target company 1 bit different from the original.
It can be used for receiving emails, phishing sites, capturing internal DNS requests that have gone rogue due to bit errors (due to anything from hardware errors to cosmic rays).
There is a really good talk by Artem Dinaburg from Blackhat about it (first talk about it? I think) https://media.blackhat.com/bh-us-11/Dinaburg/BH_US_11_Dinabu...
The talk is available here https://www.youtube.com/watch?v=9WcHsT97suU
Let’s just say that setting up a catchall for that domain generated countless hours of entertainment.
Highly unsophisticated people will put the dumbest things in emails to their bankers.
On the other hand there were rare heartbreaking instances where families would beg to find a way to keep their homes or cars.
I always forwarded those on to the intended recipient.
And this didn't generate any electronic knocks-on-your-door??
> As for all other services, we did not complete the final step of the password resets for privacy reasons meaning we did not log into or take over the user accounts, or access any information stored in online services, although we could have.
But they did read a ton of email they knew was private? Censoring it for public consumption doesn't change the fact that they accessed it.
Anybody doing this kind of thing in Australia should be familiar with the 'Cybercrime Act 2001' model. In NSW it is implemented in Part 6 of the Crimes Act 1900, and other states also mirror the Cth legislation with various modifications. Some of these (eg Criminal Code 1995 (Cth) s 478.1 / Crimes Act 1900 s 308H) are absolute liability offences, so it is not necessary to prove anything about your intent. Read the definitions in, eg, Criminal Code 1995 s 476.1 for how broad they go ('guided or unguided electromagnetic energy').
The federal offences have to be within the constitutional limits on Cth legislative power, so they 'only' apply to Cth computers/data or when 'the access to, or modification of, the restricted data is caused by means of a carriage service', i.e. The Internet. So they can usually be applied.
These provisions are extremely broad, so there's a lot resting on prosecutorial discretion. Nobody can say for sure whether these things breach the act, but there are plenty of ways to interpret the provisions and cast the actions within them. For example, they might have impaired the electronic communication to or from a computer per s 477.3, and it's not like they were asking anyone first. Also 'here are some private emails we received' is just so plausibly within 'unauthorised access to restricted data'. Probably talk to a lawyer before hitting the big Publish button on Medium Dot Com, and maybe refrain from actually deliberately receiving people's emails, especially when everyone already knows that email compromise = everything and there's nothing to prove.
https://www.legislation.gov.au/Details/C2018C00298/Html/Volu...
http://www6.austlii.edu.au/cgi-bin/viewdb/au/legis/nsw/conso...