Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
throwaway2346mg
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
throwaway2346mg
3y ago
I don't think this is related. The issue here is with inbound emails using Mailgun's inbound routes functionality. Protecting your sending servers from abuse isn't an issue with Mailgun as far as I'm aware.
2.
▲
by
throwaway2346mg
3y ago
Yep - there are a number of scenarios: - CRM system (obviously an issue) - Inbound email automation (eg. action based on reply from user / admin / etc) But really, any inbound action where you don't want someone to be able to
3.
▲
by
throwaway2346mg
3y ago
Exactly this!
4.
▲
by
throwaway2346mg
3y ago
As pointed out on Reddit [1], if you want to trivially see companies using Mailgun it's as simple as looking at: https://securitytrails.com/list/mx/mxb.mailgun.org https://securitytrails.com/l
5.
▲
by
throwaway2346mg
3y ago
I'm afraid I haven't checked this - are you a Mailgun user and want to report back on this? Alternatively, hopefully Mailgun themselves will spot this and can respond directly.
6.
▲
by
throwaway2346mg
3y ago
> Is the problem that they don't do the verifications for SPF/DKIM/DMARC for inbound emails? Yes - the result of the checks aren't passed through for inbound emails (when sent to webhooks).
7.
▲
by
throwaway2346mg
3y ago
Agreed. I think the point here is that what % of Mailgun users will be doing this additional processing? I suspect it's basically 0%. Why? It's not outlined in their specs, their sales copy implies they are handling it, and sensib
8.
▲
by
throwaway2346mg
3y ago
The sender can be anyone. They don't need to be a mailgun user. The recipient has to be a mailgun user, yes.
9.
▲
by
throwaway2346mg
3y ago
> Is that not identical to "if a company runs an SMTP server, you send a spoofed email, and they don't do any validation then phishing is trivial"? Yes. Except in this case, the company is paying Mailgun to process inbound
10.
▲
by
throwaway2346mg
3y ago
Yes - it's emails that hit a certain pre-determined spam assassin threshold (see Note B). But this is fairly easy to circumvent (spammers/phishers are especially good at it) and the threshold is reasonably high. All in all this me
11.
▲
Mailgun: Public Security Disclosure
88 points
by
throwaway2346mg
3y ago
|
30 comments
12.
▲
by
throwaway2346mg
3y ago
I'm not sure if this is relevant in regards to the security disclosure itself. If you're not using Mailgun then this doesn't affect you. However, with regards to "SPF is more than enough", the fact here is that the
13.
▲
Mailgun: Public Security Disclosure
5 points
by
throwaway2346mg
3y ago
|
2 comments