Viewing profile — throwaway2346mg
throwaway2346mg
HN member- Joined
- Mon, Jul 10, 2023, 12:17 PM UTC
- HN karma
- 35
- Public activity
- 13 items
- HN profile
- View on Hacker News ↗
About throwaway2346mg
No profile information was provided.
Recent public activity
-
comment
Comment #36692107
I don't think this is related. The issue here is with inbound emails using Mailgun's inbound routes functionality. Protecting your sending servers from abuse isn't an issue with Ma…
-
comment
Comment #36692090
Yep - there are a number of scenarios: - CRM system (obviously an issue) - Inbound email automation (eg. action based on reply from user / admin / etc) But really, any inbound acti…
-
comment
Comment #36692081
Exactly this!
-
comment
Comment #36679979
As pointed out on Reddit [1], if you want to trivially see companies using Mailgun it's as simple as looking at: https://securitytrails.com/list/mx/mxb.mailgun.org https://security…
-
comment
Comment #36679958
I'm afraid I haven't checked this - are you a Mailgun user and want to report back on this? Alternatively, hopefully Mailgun themselves will spot this and can respond directly.
-
comment
Comment #36679931
> Is the problem that they don't do the verifications for SPF/DKIM/DMARC for inbound emails? Yes - the result of the checks aren't passed through for inbound emails (when sent to w…
-
comment
Comment #36679921
Agreed. I think the point here is that what % of Mailgun users will be doing this additional processing? I suspect it's basically 0%. Why? It's not outlined in their specs, their s…
-
comment
Comment #36679286
The sender can be anyone. They don't need to be a mailgun user. The recipient has to be a mailgun user, yes.
-
comment
Comment #36679282
> Is that not identical to "if a company runs an SMTP server, you send a spoofed email, and they don't do any validation then phishing is trivial"? Yes. Except in this case, the co…
-
comment
Comment #36678900
Yes - it's emails that hit a certain pre-determined spam assassin threshold (see Note B). But this is fairly easy to circumvent (spammers/phishers are especially good at it) and th…
-
story
Mailgun: Public Security Disclosure
TLDR: Inbound email routes don't have SPF/DKIM/DMARC protection, meaning any inbound email sent to a webhook can be trivially spoofed / phished. Mailgun describe inbound routes as:…
-
comment
Comment #36665829
I'm not sure if this is relevant in regards to the security disclosure itself. If you're not using Mailgun then this doesn't affect you. However, with regards to "SPF is more than …
-
story
Mailgun: Public Security Disclosure
TLDR: Inbound email routes don't have SPF/DKIM/DMARC protection, meaning any inbound email sent to a webhook can be trivially spoofed / phished. Mailgun describe inbound routes as:…