GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Mike Sheward (secureowl@infosec.exchange)

  1. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 13-May-2026 12:09:16 JST Mike Sheward Mike Sheward
    in reply to

    UPS delivery today - photo taken - no hits on the canary, which means Amazon still remains the only deliverer to have triggered it

    In conversation about 2 days ago from infosec.exchange permalink
  2. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 13-May-2026 12:09:16 JST Mike Sheward Mike Sheward
    in reply to

    Experiment update

    Amazon are 2/2 for hitting the QR canary token - same CDN, same non-phone user agent each time. Seems to happen async after the delivery, maybe 20 mins or so later.

    Actual delivery photo from today below.

    Only other test subject so far is Fedex, they did not trigger the QR.

    #infosec

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/511/720/676/152/306/original/a62bb20fca284f6d.jpeg
  3. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 13-May-2026 12:09:15 JST Mike Sheward Mike Sheward
    in reply to

    Update on my QR porch ornament experiment.

    There have now been 4 Amazon proof of delivery images containing the code.

    The first two, reliably hit the canary token within 20-40 minutes of the delivery, from a non-phone QR code. Definitely some sort of automated process.

    The third one, did hit the QR, but it was because the delivery person took it upon themselves to scan the QR code with their phone to see what it did - user agent confirmed that. There were no programatic hits like the first two.

    Fourth one, in the picture, but no hit registered.

    UPS/FedEx/USPS - not even as much as a flicker of a GET request to my canary.

    Bonus points, while driving I exposed my QR code to a couple of Flock cameras, but alas they didn't do anything.

    Next step will be a new QR code, one that points to a different domain, because the next thing to check is - did they start blocking the requests to Canarytoken dot org from whatever process was ingesting the images - because that is what it seems like.

    In conversation about 2 days ago from infosec.exchange permalink
  4. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 13-May-2026 12:09:15 JST Mike Sheward Mike Sheward
    in reply to

    delivery person today put package actually on top of the QR code so it wasn’t in the POD photo

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/535/532/491/925/649/original/f9c618015dc17eda.jpeg
  5. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 13-May-2026 02:00:31 JST Mike Sheward Mike Sheward

    they paid a ransom to criminals with nothing but a pinky promise they wouldn’t do more crimes and yet this linkedin notification makes it sound like they entered into a strategic partnership to deliver value for their customers

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/194/827/951/503/original/2b095e943faaa627.jpeg
  6. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Monday, 11-May-2026 09:39:06 JST Mike Sheward Mike Sheward

    “Hi, my name’s David, I’m one of the repair techs here, I’v been looking after your broken soldering iron today.”

    “How’s he doing.”

    “Take a seat.”

    “Oh no.”

    “Unfortunately, and there is no easy way to say this, we looked at your Iron, and, well, we found something.”

    “Please, just give it to me straight.”

    “Ok, well we found, and I’m so sorry, we found, firmware.”

    “It has firmware?”

    “Yes.”

    “But it’s a soldering iron?”

    “Yes.”

    “So there is nothing you can do for it?”

    “Unfortunately, when a tool has firmware, it’s always fatal. There is nothing we can do. I am very sorry.”

    “But, it’s so young. I only got it like a month or so ago?”

    “Sadly, we often see firmware on younger tools.”

    “But it was fine yesterday, like totally fine?!”

    “With any kind of firmware, it can just, you know, stop working.”

    “What am I gonna tell the kids?!”

    “Obviously you know your kids better than me, but as a general rule, I always tell people that kids appreciate honesty, and are more resilient than you might think. Be honest.”

    “But how?”

    “Just tell them, you were drawn in by the features, rather than just a functional thing, so that’s why you got it.”

    “Ah man this is going to be rough.”

    “Would you like to see him?”

    “Not like this.”

    #microfiction

    In conversation about 4 days ago from infosec.exchange permalink
  7. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Sunday, 10-May-2026 03:31:40 JST Mike Sheward Mike Sheward

    For fans of @acarsdrama - it is now regularly receiving and churning through 250,000 raw messages an hour from the skies around the globe. That is insane.

    In conversation about 5 days ago from infosec.exchange permalink
  8. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Saturday, 02-May-2026 11:49:26 JST Mike Sheward Mike Sheward

    when people say “america 250” they are actually talking about the number of fellas who own the place

    In conversation about 13 days ago from infosec.exchange permalink
  9. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Friday, 01-May-2026 17:37:48 JST Mike Sheward Mike Sheward

    trying a new thing, have 3D printed a QR code and put it on the front porch

    QR code triggers a canary token

    want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

    #infosec

    In conversation about 14 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/496/625/085/115/337/original/fbe395230d1e42df.jpeg
  10. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Friday, 01-May-2026 17:37:47 JST Mike Sheward Mike Sheward
    in reply to

    Whelp, sample size of 1 so far, but about 50 minutes after an amazon delivery - where a picture was taken - got a hit on the canary

    i just checked the delivery photo and the QR code was visible in it

    User agent was not a phone and clearly some sort of crawler

    IP address was a CDN

    but we are 1/1, lets see how it goes with a few more

    (i get a lot of random work deliveries)

    In conversation about 14 days ago from infosec.exchange permalink
  11. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:49 JST Mike Sheward Mike Sheward
    in reply to

    side note: i made up an account deletion process that included the deleteduser.com thing for emails and asked ChatGPT if it was cool.

    the word order guessing machine said it was cool

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments



    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/443/985/595/651/164/original/296dd9bd43ccd431.jpeg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/443/985/581/523/254/original/fdc7f3f1a41beb99.jpeg
  12. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:49 JST Mike Sheward Mike Sheward
    in reply to

    Thought of another potential vector here.

    You know how some SaaS products, particularly enterprise ones, let you join a workspace/tenant by providing an email address at a given domain, so if you sign in with companya.com you go to Company A's tenant.

    Yeah...I wonder how many surprises lurk if you sign in with deleteduser.com or any of the other plexfiltration domains....

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      company A
  13. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:48 JST Mike Sheward Mike Sheward
    in reply to

    Ok, if you are particularly sensitive to the effects of irony, I suggest you take a seat before reading further.

    In what is perhaps the most perfect encapsulation of everything that this experiment has shown so far, last night, deleted-user.com received over 400 emails from the same organization.

    This was an EU based tech firm.

    The purpose of those emails? They were from the company's legal team, advising users of updated terms and conditions, and the first update was:

    "Data protection: we added language explaining how we handle personal data under the GDPR"

    #infosec #gdpr

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.hitmedia.in
      Under Construction

  14. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:48 JST Mike Sheward Mike Sheward
    in reply to

    Super interesting to note that, in the case of the internaluser.com defense contractor thingy, they must've realized their mistake very quickly - because there was a follow up email within the hour informing the @internaluser.com email that their email address on the system had been changed.

    Unfortunately, that change did reveal an internal domain used by said defense contractor.

    That's the thing with Plexfiltration, when it gets ya it's hard to escape without it getting ya some more.

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments


  15. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:48 JST Mike Sheward Mike Sheward
    in reply to

    internaluser.com has delivered again (the second busiest plexfiltration domain, after deleteduser.com)

    This time, it has served up a password reset link for a web application operated by a major US defense contractor.

    Seems fine.

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments



  16. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:47 JST Mike Sheward Mike Sheward
    in reply to

    One more new one today, some Australian restaurant thingy - nothing too crazy on its own, but they get a special shout out for....drumroll.....

    De-identifying the names and other PII of their deleted users by Base64 encoding them!

    In conversation about 16 days ago from infosec.exchange permalink
  17. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:47 JST Mike Sheward Mike Sheward
    in reply to

    Couple of new welcomes to the internet PII dumpster overnight:

    - An app that manages payments for Car Washes - sent me full names, license plates of vehicles associated with a deleted account.

    - EU based Microsoft Training Partner's privacy officer sent me a nice note sharing the email addresses of two people who had asked to be deleted, confirming that they had been deleted.

    But a couple of good updates too:

    - Nice email from UK ICO saying 'thanks for bringing this to our attention'.

    - Email from the company that sent out 400+ emails in a single day saying, 'yikes thanks, we've passed this on internally'.

    In conversation about 16 days ago from infosec.exchange permalink
  18. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:47 JST Mike Sheward Mike Sheward
    in reply to

    Got a second reply from a company. Don't think they really understood what I was saying as the reply was:

    "Hi Mike,

    Thank you for reaching out and expressing your interest in collaborating. At this time, we are not engaging in new marketing partnerships, guest posts, or link exchanges, but we will be sure to notify you should this change in the future."

    K.

    In conversation about 16 days ago from infosec.exchange permalink
  19. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:47 JST Mike Sheward Mike Sheward
    in reply to

    In case you were wondering about the stats, 55 orgs have been contacted about this practice, 1 has responded with a 'woah, shit, thanks'.

    In conversation about 16 days ago from infosec.exchange permalink
  20. Embed this notice
    Mike Sheward (secureowl@infosec.exchange)'s status on Wednesday, 29-Apr-2026 09:37:46 JST Mike Sheward Mike Sheward
    in reply to

    I just got given admin access to some Medicaid filing platform because I own the domain internaluser.com

    #infosec

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments


  • Before

User actions

    Mike Sheward

    Mike Sheward

    Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          43307
          Member since
          30 Nov 2022
          Notices
          187
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.