Live data from Hacker News

Reading Uber’s Internal Emails: Bug Bounty report worth $10K

blog.pentestnepal.tech

1–10 of 55 posts

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#2
Ouch. No domain verification required by Sendgrid before allowing you to inject a hook that dumps email contents.

That's much broader than just Uber.

Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#4
Totally just curious. The law for "exceeds authorized access" is 20 years in prison. I think uber has a bug fixing program. Maybe sendgrid does? Do the DNS carriers? Does his ISP? I read the law. If one of these companies refutes access - this guy is facing 20 years [1]? W(why)TF do people do this? The US government is notoriously creative in these prosecutions [3]. Companies refute access all the time to not look like idiots EVEN WITH a bounty program. [2]. If I came across this I wouldn't be blogging about it for 10k?

[1] "(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—(C) information from any protected computer;" (C) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than 20 years, or both, in the case of—"

https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

[2] http://motherboard.vice.com/blog/facebook-is-refusing-to-pay...

[3] https://en.wikipedia.org/wiki/Aaron_Swartz

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#5
post #3

This looks like a massive security flaw on sendgrid's side. They should use DNS validation like everybody else to prove ownership of the subdomain.

From the article:

>Also at the moment of writing this bug, it has come to my attention that SendGrid has added extra verification which forces you to have a verified domain before adding a inbound parse webhook.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#6
post #2

Ouch. No domain verification required by Sendgrid before allowing you to inject a hook that dumps email contents. That's much broader than just Uber. Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.

From the article:

>Also at the moment of writing this bug, it has come to my attention that SendGrid has added extra verification which forces you to have a verified domain before adding a inbound parse webhook.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#7

Totally just curious. The law for "exceeds authorized access" is 20 years in prison. I think uber has a bug fixing program. Maybe sendgrid does? Do the DNS carriers? Does his ISP? I read the law. If one of these companies refutes access - this guy is facing 20 years [1]? W(why)TF do people do this? The US government is notoriously creative in these prosecutions [3]. Companies refute access all the time to not look li…

Uber's bug bounty program seems like explicit permission to me. The twist here, as you mention, is that it is sendgrid's infrastructure. Chasing bug bounties does seem a bit risky in this "cloud" era where it's not just one entity running the targeted service.

Re: Reading Uber’s Internal Emails: Bug Bounty report worth $10K

#9
The last time there was a SendGrid article on here, the feedback from the community was far from kind [0]. I again re-iterate that SendGrid has no business sending emails [1].

[0]: https://news.ycombinator.com/item?id=12142728 [1]: https://news.ycombinator.com/item?id=12145019

Post reply on HN