메뉴
HN
Hacker News • 172일 전

내 이메일이 블랙홀에 빠진 사연

IMP
5/10
핵심 요약

2000년대 초반, '카운터 스트라이크(CS)'의 인기 맵 제작자가 웜 바이러스의 대규모 스팸 공격으로 인해 자신의 소중한 개인 이메일을 영구 삭제(블랙홀 처리)해야 했던 경험을 회고한 글입니다. 당시 이메일 웜 바이러스가 사용자의 주소록뿐만 아니라 PC 내 문서 파일에서도 이메일 주소를 무차별적으로 수집해 전파되는 방식으로 진화하면서, 게임 내 크레딧에 이메일을 적어둔 제작자는 하루 수천 통의 웜 메일을 받게 되었습니다. 결국 사서함 용량 초과와 인터넷 계정 해지 위기까지 몰리며 보내고 받는 메일이 모두 차단되는 이메일 '블랙홀' 상태에 돌입하게 됩니다.

번역된 본문

개인적인 경험상, 자신의 이메일 서비스 제공자에게 주요 개인 이메일 주소를 블랙홀(수신 및 송신 영구 차단) 처리해 달라고 요청하는 상황은 그다지 흔하게 발생하지 않습니다. 하지만 2002년, 밀레니엄 전환기에 발생한 독특한 연쇄 사건들로 인해 브로드밴드(초고속 인터넷) 계정이 해지되는 것을 막기 위해 저는 정확히 그런 조치를 취해야만 했습니다.

당시 저는 dv@btinternet.com이라는 주소의 소유자였습니다. 우리 인터넷 서비스 제공업체(ISP)의 다른 가입자들이 'Dave', 'DaveJ'는 물론 제 이름과 성을 조합한 사용 가능한 모든 변형을 이미 차지한 상태였기에, 이 주소를 갖게 된 것을 자랑스럽게 여겼습니다. 'Dave'와 비슷하면서도 단 2글자로 이루어진 사용 가능한 아이디를 찾은 것은 행운이라고 생각했습니다.

2000년대 초반은 전염성이极强的인 이메일 웜의 등장으로 인해 이메일 사용에 있어 매우 까다로운 시기였습니다. 아마도 가장 악명 높았던 'ILOVEYOU' 웜은 수많은 컴퓨터 네트워크, 학교, 기업 및 지역 사회를 마비시키며 전 세계적인 이목을 끌었습니다. 이 파괴적인 바이러스는 파일을 삭제하고, 불운한 수신자(물론 아웃룩을 사용하는)의 주소록에 있는 모든 사람에게 자신을 이메일로 전송하는 방식으로, 경우에 따라 시스템을 완전히 파괴하기도 했습니다. 2000년에만 해도 그 피해자 수는 수백만 명에 달했습니다.

2002년이 되자, 이러한 웜 바이러스 제작자들이 더 넓고 빠르게 확산을 시도하면서 웜은 상당히 정교해지고 은밀해졌습니다. 적어도 저의 불쌍한 받은편지함에 있어 가장 파괴적이었던 변화는, 잠재적 대상의 이메일 주소를 사용자의 주소록뿐만 아니라 하드 디스크에 있는 모든 텍스트 형식의 파일에서 추출할 수 있게 된 점입니다.

이쯤에서 저는 '더스트 2(Dust 2)'를 포함해 네 번째 공식 CS(카운터 스트라이크) 맵을 제작한 상태였습니다. 이는 모든 CS 설치 파일에 제 개인 이메일 주소가 최소 4번은 명시되어 있음을 의미했습니다. 누군가 제가 만든 맵을 구동하는 서버에 접속할 때마다 미션 브리핑의 일부로 이 이메일 주소가 매번 화면에 나타났습니다.

Dust - Bomb/Defuse by DaveJ (dv@btinternet.com) textures by Macman (MacManInfi@aol.com) Counter-Terrorists: Prevent Terrorists from bombing chemical weapon crates. Team members must defuse any bombs that threaten targeted areas. Terrorists: The Terrorist carrying the C4 must destroy one of the chemical weapon stashes. Other Notes: There are 2 chemical weapon stashes in the mission. (Press FIRE to continue)

이것이 바로 de_dust.txt 파일의 내용이었으며, Dust 2와 Cobble에도 동일한 형식의 파일이 존재했고 전체 readme.txt 파일에도 포함되어 있었습니다. 당시 가장 인기 있던 멀티플레이어 FPS 게임의 모든 설치 파일 어딘가에 기여자들의 이메일이 적혀 있었습니다. 이 게임은 주로 인터넷에 연결된 컴퓨터에 설치되었고, 그 시대는 오직 인터넷을 통해서만 확산되는 독성이 강한 이메일 웜이 창궐하던 시기였습니다. 독자분들도 이 상황이 어디로 향하는지 짐작하실 수 있을 것입니다...

저의 dv@btinternet.com 계정은 곧 'Klez'와 같은 웜으로 인해 하루에 수십 통, 이내 수백 통의 이메일을 받기 시작했고, 그 수가 너무 많아져서 (다행히 패치된 상태였던 저의) 아웃룩은 더 이상 받은편지함을 로드할 수조차 없게 되었습니다. 그래서 정상적인 메일을 통과시키기 위해 문제가 되는 이메일을 미리 빠르게 스캔하고 삭제할 수 있는 전용 POP3 도구를 사용해야만 했습니다.

다행히도 삭제해야 할 이메일들은 제목 줄의 공통적인 패턴으로 쉽게 식별할 수 있었기 때문에, 받은편지함 접근을 복원하는 데는 하루에 불과 몇 분밖에 걸리지 않았습니다. 안타깝게도 이런 평화는 오래가지 않았습니다. 하루에 수백 통의 이메일을 받던 것이 곧 하루에 수천 통으로 늘어났고, 이는 당시로서는 넉넉하다고 여겨지던 저희 ISP인 BT(British Telecom)에서 관대하게 부여한 15MB의 사서함 용량을 가뿐히 채우고도 남았습니다.

더 최악인 점은, 웜 제작자들이 대량 식별 및 제거를 회피하기 위해 이메일 구조에서 꽤 창의적인 방법들을 사용하기 시작했다는 것입니다. 이들은 무작위로 생성된 제목과 본문, 위조된 헤더, 훔쳐온 파일 첨부를 활용했으며, 가장 짜증나게도 자신들이 발견한 주소록이나 파일에서 수집한 데이터를 이용해 발신자 주소를 스푸핑(위조)했습니다.

아버지(실제 계정 소유자)는 이메일 사용에 대한 경고를 받기 시작했고, 우리의 브로드밴드 계정은 해지될 위기에 처했습니다. 게임은 끝났습니다. 저의 소중한 2글자 이메일 주소는 결국 블랙홀에 빠지고 말았습니다.

원문 보기
원문 보기 (영어)
In my own experience, it’s not particularly often that you find yourself asking your email provider to blackhole your primary, personal email address. But in 2002, a unique series of turn-of-the-millennium events had me doing exactly that to prevent our broadband account from being terminated. Back then, I was the owner of dv@btinternet.com - proudly so, as all other acceptable variations of “Dave”, “DaveJ”, and my firstname/surname appeared to have been taken by other subscribers to our ISP. To find an available 2-letter username that was vaguely similar to “Dave” felt lucky. The early 2000s were challenging for email, thanks to the emergence of highly-transmissable email worms. Perhaps most famously, the “ILOVEYOU” worm earned international attention as thousands of computer networks, schools, businesses and communities were brought down - in some cases destroyed - by virtue of this destructive virus deleting files and emailing itself to everyone who happened to be in the address list of any unfortunate (albeit Outlook-using) recipient. Even in 2000, that was millions upon millions of people. By 2002 these worms had evolved to become considerably more sophisticated - and sneaky - as their authors attempted to spread wider and faster. One of the most devastating changes - at least for my poor, poor inbox - was the ability to source email addresses of potential targets not just from the users address book, but from any and every text-like file on the user’s hard disk. At this point I was onto my fourth official CS map - Dust 2 - which meant at least 4 mentions of my personal email address in every CS installation. An email address that would pop up every time someone connected to a server running one of my maps, as part of the mission briefing: Dust - Bomb/Defuse by DaveJ (dv@btinternet.com) textures by Macman (MacManInfi@aol.com) Counter-Terrorists: Prevent Terrorists from bombing chemical weapon crates. Team members must defuse any bombs that threaten targeted areas. Terrorists: The Terrorist carrying the C4 must destroy one of the chemical weapon stashes. Other Notes: There are 2 chemical weapon stashes in the mission. (Press FIRE to continue) This was de_dust.txt - equivalents existed for Dust 2 and Cobble, plus the overall readme.txt . All contributors to CS had their email listed somewhere in every single installation of the most popular multiplayer FPS of the time, a title primarily installed onto internet-connected computers, during a period of highly virulent email worms that spread exclusively via the internet. You see where this is going… My dv@btinternet.com account soon started receiving tens, and then hundreds, of emails a day from worms such as “Klez” - so many that Outlook (mine was patched, thankfully) could no longer load my inbox anymore. I had to use a dedicated POP3 tool that would let me rapidly scan and remove troublesome emails beforehand to let the legitimate ones through. Mercifully, trashable emails were easily identified by common patterns in the subject line, so this only took a few minutes a day to restore inbox access. Alas, this didn’t last. Before long those few hundred emails a day I was receiving became thousands of emails a day, which easily occupied the entirety of the at-the-time generous 15MB (megabytes!) of mailbox space so gracefully bestowed to me by BT, our ISP. Worst still, worm authors had become somewhat more creative with their email structure to evade bulk identification and removal, utilising randomly-constructed subject lines, bodies, feigned headers, stolen file attachments, and - most annoyingly - using spoofed sender addresses, again using harvested data from whatever address books and files they came across. My dad (the actual account holder) started to receive warnings about email usage. Our broadband account faced the risk of closure. The game was up. My precious 2-letter email address was unusable - any valid emails were being completely lost amongst all the infected ones, my inbox was too full to receive new emails, and even many of the valid ones that did get through were accusations of me sending them a worm (remember those spoofed headers?) I had little choice but to ask BT Customer Service to blackhole dv@btinternet.com to save our account, to protect their email service, and to prevent creating a storm of unexpected bounced emails to the poor souls whose addresses had been randomly chosen as the spoofed “from” address. 24 years later, and my dad’s BT Internet account is still around. Out of curiosity, I tried to log in and see if I could find the current state of dv@btinternet.com - but that functionality was removed some years ago, and it’s not possible to create new inboxes anymore. I tried sending an email to it - and got a regular “User unknown” reply back, indicating that at some point the blackhole was removed, and the account simply became non-existent. I’d be curious to know if it is still receiving any email worms all these years later.