“I Emailed 97,931 Users Their Passwords”
atechdad.com
atechdad.com
You can find the code here: http://github.com/jordan-wright/dumpmon.
Here are some stats if anyone is interested in what it collected over approx. 2 years: http://jordan-wright.com/blog/2015/05/26/two-years-of-at-dum...
Glad to see dumpmon is still going strong :)
Took much inspiration from dumpmon, but distributed it so users can choose their own sensitivity settings.
> The thank you notes I got were sincere. One of them validated the entire effort when the person indicated that they use the same password for everything and wanted to know which account had been compromised
I hope they don't only change the password on that one site!
If someone had just sent me an email letting me know that my email and password are out there in the wild, "fuck off" would not be my first reaction. That's just rude.
Unsolicited automated email = Spam.
Unsolicited semi-automated (i.e. fill in the blanks) email = Spam.
Unsolicited personal email actually written by a human = OK.
Followup to unsolicited email because I didn't reply to the first one = Very rude. Instant blacklist of sender.
Also for ref: http://dontevenreply.com/view.php?post=99
Really? This guy emailed 97,000 people and you're just going to assume they're all just like you? :)
In this list, with near certainty there will be all of the following: children, teenagers, people having a really really shitty day, dogs, criminals, mentally ill, and possibly indeed also a few who are "just rude" ...
Frankly it surprises me he only got one "fuck off" reply.
Sorry about that.
My biggest concern is that your subject line sounds like plenty of spam/phishing emails, and your URL may get blacklisted by email services if you do this often enough.
From a slightly higher effort standpoint, you might be able to work with major email service providers to ship these notifications to users in a more official capacity.
Maybe putting the scraped password in the subject line catches the recipients' attention.
The biggest problem is being prone to misinformation. There's nothing to prevent people from posting arbitrary e-mail lists to pastebin, with purported matching passwords, as an effort to provoke your service to cry wolf.
A few suggestions to harden the service:
- provide integrity when sending the message by including a PGP signature. what's to stop someone from running an e-mail server and spamming mass e-mail lists with message headers that spoof your mail domain, and proclaim bogus security lapses?
- in general, e-mail itself is not assuredly secure. sending people an e-mail is not enough, since the message might be intercepted as plaintext, and altered in transit. furthermore, those intercepting the e-mail might scoop up credentials and use them. if your service is a reliable source of working credentials, who better to attack? maybe you risk making the problem worse?
- consider hosting a secure web page over SSL, and mail links to your site. if your service gains a positive reputation, users might be able to acknowledge past leaks, but elect to receive further notices if other leaks recur elsewhere. maybe users can see links to the source someone is using to post their info, and whether the situation has been remedied by a take-down. this might be a questionable activity: if you send people to that same breach, will they look at the same list and abuse other users on the list? but what better way to demonstrate the breach?
- provide a means to verify the level exposure. what if someone's account was listed for 24 hours, and then the leak was taken down. they might still wish to know they were exposed, so they can take action. also, is the resource you're linking to confirmed as related to a known/verified data breach? who confirmed that this was a real breach of security? are you a first responder to the leak? has the leak been responsibly disclosed to the providers of the accounts tied to the leaked passwords?
This is a good point, but wouldn't use of SPF/DKIM solve this too? I think email servers are able to understand the SPF records and DKIM-Signature header and hence more accurately classify the emails as spam (if appropriate) which seems like a useful benefit.
I don't know if this is a service that can be maintained for any period of time, but hopefully the unexpected emails helped someone before the service could be abused.
Your password is: xttp://someporn.site.the/spammer_wants_you_to_visit
If you're going to continue doing this, you might want to take a look at the message you're sending (or have someone else do that for you). Remember that a large segment of your recipients are probably not the most tech-savvy (or brightest). Do not overestimate random users reading comprehension. Without clear explanation where these passwords came from the natural assumption is that you did it, and you're warning them as a threat. No that doesn't make sense but remember who you're talking to.
One more thing:
> the person indicated that they use the same password for everything and wanted to know which account had been compromised.
If you answered that, you may just have got social engineered.
> Gmail automatically shows you the images in your messages
It does have an option to turn it off, but the default is on. They will load up the image themselves, then serve it from their domain, but, as the help information shows, that still indicates an "open", it's just that all the information on who opened the email (IP address, etc) would be wrong.
One source: http://arstechnica.com/information-technology/2013/12/gmail-...
EDIT: I get what you're saying. I guess the count would depend on how long Google caches that image- or do they load it on a per email basis?
This'll only work on very very old desktop clients, or users that actually click the "show images" button.