Reading Uber’s Internal Emails: Bug Bounty report worth $10K
blog.pentestnepal.tech
Reading Uber’s Internal Emails: Bug Bounty report worth $10K
1–10 of 55 posts
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#2That's much broader than just Uber.
Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#3Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#4[1] "(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—(C) information from any protected computer;" (C) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than 20 years, or both, in the case of—"
https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
[2] http://motherboard.vice.com/blog/facebook-is-refusing-to-pay...
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#5This looks like a massive security flaw on sendgrid's side. They should use DNS validation like everybody else to prove ownership of the subdomain.
>Also at the moment of writing this bug, it has come to my attention that SendGrid has added extra verification which forces you to have a verified domain before adding a inbound parse webhook.
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#6Ouch. No domain verification required by Sendgrid before allowing you to inject a hook that dumps email contents. That's much broader than just Uber. Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.
>Also at the moment of writing this bug, it has come to my attention that SendGrid has added extra verification which forces you to have a verified domain before adding a inbound parse webhook.
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#7Totally just curious. The law for "exceeds authorized access" is 20 years in prison. I think uber has a bug fixing program. Maybe sendgrid does? Do the DNS carriers? Does his ISP? I read the law. If one of these companies refutes access - this guy is facing 20 years [1]? W(why)TF do people do this? The US government is notoriously creative in these prosecutions [3]. Companies refute access all the time to not look li…
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#8Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#9[0]: https://news.ycombinator.com/item?id=12142728 [1]: https://news.ycombinator.com/item?id=12145019
Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K
#10It's just me, or $10k is far from being generous?