Live data from Hacker News

Viewing profile — throwaway2346mg

throwaway2346mg

HN member
Joined
Mon, Jul 10, 2023, 12:17 PM UTC
HN karma
35
Public activity
13 items

About throwaway2346mg

No profile information was provided.

Recent public activity

  1. comment
    Comment #36692107

    I don't think this is related. The issue here is with inbound emails using Mailgun's inbound routes functionality. Protecting your sending servers from abuse isn't an issue with Ma…

  2. comment
    Comment #36692090

    Yep - there are a number of scenarios: - CRM system (obviously an issue) - Inbound email automation (eg. action based on reply from user / admin / etc) But really, any inbound acti…

  3. comment
    Comment #36692081

    Exactly this!

  4. comment
    Comment #36679979

    As pointed out on Reddit [1], if you want to trivially see companies using Mailgun it's as simple as looking at: https://securitytrails.com/list/mx/mxb.mailgun.org https://security…

  5. comment
    Comment #36679958

    I'm afraid I haven't checked this - are you a Mailgun user and want to report back on this? Alternatively, hopefully Mailgun themselves will spot this and can respond directly.

  6. comment
    Comment #36679931

    > Is the problem that they don't do the verifications for SPF/DKIM/DMARC for inbound emails? Yes - the result of the checks aren't passed through for inbound emails (when sent to w…

  7. comment
    Comment #36679921

    Agreed. I think the point here is that what % of Mailgun users will be doing this additional processing? I suspect it's basically 0%. Why? It's not outlined in their specs, their s…

  8. comment
    Comment #36679286

    The sender can be anyone. They don't need to be a mailgun user. The recipient has to be a mailgun user, yes.

  9. comment
    Comment #36679282

    > Is that not identical to "if a company runs an SMTP server, you send a spoofed email, and they don't do any validation then phishing is trivial"? Yes. Except in this case, the co…

  10. comment
    Comment #36678900

    Yes - it's emails that hit a certain pre-determined spam assassin threshold (see Note B). But this is fairly easy to circumvent (spammers/phishers are especially good at it) and th…

  11. story
    Mailgun: Public Security Disclosure

    TLDR: Inbound email routes don't have SPF/DKIM/DMARC protection, meaning any inbound email sent to a webhook can be trivially spoofed / phished. Mailgun describe inbound routes as:…

  12. comment
    Comment #36665829

    I'm not sure if this is relevant in regards to the security disclosure itself. If you're not using Mailgun then this doesn't affect you. However, with regards to "SPF is more than …

  13. story
    Mailgun: Public Security Disclosure

    TLDR: Inbound email routes don't have SPF/DKIM/DMARC protection, meaning any inbound email sent to a webhook can be trivially spoofed / phished. Mailgun describe inbound routes as:…