Live data from Hacker News

Reading Uber’s Internal Emails: Bug Bounty report worth $10K

blog.pentestnepal.tech

31–40 of 55 posts

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#31
post #2

Ouch. No domain verification required by Sendgrid before allowing you to inject a hook that dumps email contents. That's much broader than just Uber. Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.

I believe they did retroactively search for accounts.

Source: I had a number of accounts banned when testing different iterations of this bug.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#32
post #11

Someone reported this same vulnerability to us via HackerOne months ago. We worked with Sendgrid support to re-claim the domain and they said they were urgently working to fix the issue, or not. Edit: just saw this post was from September. Author probably made thousands in rewards circulating this vulnerability.

I do not believe the author circulated this report to multiple companies, however once it was made public a number of other reporters in the community did and continued to iterate on it until SendGrid fixed the issues.

Source: I am a member of said community: https://bugcrowd.com/bored-engineer, https://hackerone.com/bored-engineer, etc

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#33
post #3

This looks like a massive security flaw on sendgrid's side. They should use DNS validation like everybody else to prove ownership of the subdomain.

Technically they did employ some DNS validation. You had to setup a MX record to point to SendGrid before you could add the domain to your account. The problem was in order to send emails from a domain you had to add the same MX record. If you never setup the receiving end as well (on SendGrid) you were vulnerable to a takeover from another SendGrid account.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#34
post #8

It's just me, or $10k is far from being generous?

Why does this comment appear on every bug bounty HN thread? Straight from the horse's mouth [0]:

  The black market is very unlikely to be a place you could sell a bug in a specific 
  website or service. It is not “worth millions”. Please stop repeating this.
[0] - https://medium.com/@collingreene/to-the-bounty-hunters-9259b...

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#35

Earlier quoted context omitted.

As a former customer (it has admittedly been a few years) I'm not surprised. Sendgrid's entire business is based on price. Emails are one of the few costs that don't really scale that well. They cost a lot more than people think they should. When I list did a cost analysis they beat out a lot of other providers. I haven't used them in years, so I'm not sure if they are still the low cost leader, but they are definite…

Who would you recommend then?

I'm not the person you asked but I too have had bad experiences with SendGrid.

It really depends on which aspect of SendGrid we're talking about.

Transactional e-mail? Mailgun is a easy to use API on top of Amazon's SES.

You can even set up incoming e-mail hooks e.g. "When a new e-mail arrives, POST the contents to this address and attach any attachments on the e-mail as file uploads."

Newsletters? Drip campaigns? I have less experience on this side of the realm, but HubSpot has been the best experience I've seen. Their web management UI is also powered by their own open API, if I remember correctly.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#36

Earlier quoted context omitted.

As a former customer (it has admittedly been a few years) I'm not surprised. Sendgrid's entire business is based on price. Emails are one of the few costs that don't really scale that well. They cost a lot more than people think they should. When I list did a cost analysis they beat out a lot of other providers. I haven't used them in years, so I'm not sure if they are still the low cost leader, but they are definite…

Who would you recommend then?

Not Marketo

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#37

Earlier quoted context omitted.

As a former customer (it has admittedly been a few years) I'm not surprised. Sendgrid's entire business is based on price. Emails are one of the few costs that don't really scale that well. They cost a lot more than people think they should. When I list did a cost analysis they beat out a lot of other providers. I haven't used them in years, so I'm not sure if they are still the low cost leader, but they are definite…

Who would you recommend then?

I've had good experiences with Postmark, though I haven't tried them at large scale.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#38
post #8

It's just me, or $10k is far from being generous?

Why does this comment appear on every bug bounty HN thread? Straight from the horse's mouth [0]: The black market is very unlikely to be a place you could sell a bug in a specific website or service. It is not “worth millions”. Please stop repeating this. [0] - https://medium.com/@collingreene/to-the-bounty-hunters-9259b...

What a cute strawman (and completely incorrect strawman from the wrong horse at that, this is Trumpist drivel from the guy who runs the actual bug bounty who of course has some acute rationalizations for underpaying for some of the most intricate technical work in the industry).

Nobody said it was "worth millions" but I have second-degree connections in Scandinavia that would pay 10x, like I said ($100,000).

@collingreene doesn't sound too familiar with these rather-illicit organizations, he strikes me as a product manager type person with a loud voice, not someone who actually has found and sold zero-days before. Maybe he doesn't have the technical acumen to do so, but hey, I'm not one to judge.

It's hard to establish proof that the market value on the black market is, in fact, much higher given that it is the black market (you're not going to find these people on Medium); However, one public example of this is the leaked Stuxnet details showing similarly high 5-digit prices for zero-days.

This isn't a specific bug either (it wasn't "oh, the log files for that one UberEATS micro-service were visible"), this flaw allows you to intercept the emails of pretty much any single one of SendGrid's clients. Imagine the damage someone could do with that, had it gotten into the wrong hands. Only $10k, what an insult.

EDIT: Upon further examination, it turns out that said author also contradicts himself and corroborates my own argument:

https://medium.com/@collingreene/why-product-security-is-har...

Primary source: https://www.wired.com/2016/09/top-shelf-iphone-hack-now-goes...

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#39

Earlier quoted context omitted.

Who would you recommend then?

I've had good experiences with Postmark, though I haven't tried them at large scale.

I would recommend them too, I had a bad experience with sensgrid. Went from mandril to sendgrid to postmark and couldn't be happier.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#40

The last time there was a SendGrid article on here, the feedback from the community was far from kind [0]. I again re-iterate that SendGrid has no business sending emails [1]. [0]: https://news.ycombinator.com/item?id=12142728 [1]: https://news.ycombinator.com/item?id=12145019

You "again reiterate?" Do you know what those two words mean?
Post reply on HN