Reading Uber’s Internal Emails: Bug Bounty report worth $10K
blog.pentestnepal.tech
blog.pentestnepal.tech
The vulnerability is that any SendGrid user could configure a webhook callback which would POST back all received emails for any domain which had its MX set to 'mx.sendgrid.net'. OP exploited this against Uber to receive copies of their emails.
Presumably there was no way to tell from one account that another account is web-hooking your email out from under you. So you have to wonder, if it's as easy as just typing the domain you want to listen in on.... who else was getting all their emails tapped this way?
From Sendgrid's documentation;
Setup
The following steps are required to begin
parsing email:
Point the MX Record of a Domain/Hostname or
Subdomain to mx.sendgrid.net
Associate the Domain/Hostname and the URL in
the Parse API settings page.
Shocking omission by Sendgrid, where's their write-up and apology?Then they had the gall to try to convince me on the phone that it must have been my fault (after our blog post about it blew up).
Needless to say, I think they are terrible.
Previous HN discussion: https://news.ycombinator.com/item?id=7476836
I haven't used them in years, so I'm not sure if they are still the low cost leader, but they are definitely the kind of thing where you get what you pay for. Their lack of investment in product and infrastructure showed for the years I used them, and their slowness in delivering updates was incredibly frustrating.
It really depends on which aspect of SendGrid we're talking about.
Transactional e-mail? Mailgun is a easy to use API on top of Amazon's SES.
You can even set up incoming e-mail hooks e.g. "When a new e-mail arrives, POST the contents to this address and attach any attachments on the e-mail as file uploads."
Newsletters? Drip campaigns? I have less experience on this side of the realm, but HubSpot has been the best experience I've seen. Their web management UI is also powered by their own open API, if I remember correctly.
[0]: https://news.ycombinator.com/item?id=12142728 [1]: https://news.ycombinator.com/item?id=12145019
That's much broader than just Uber.
Edit: Yes, it's been fixed, but the fact that it existed for quite some time is still troubling. I'm also curious if the fix retroactively disabled any existing unverified hooks.
Source: I had a number of accounts banned when testing different iterations of this bug.
[1] "(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—(C) information from any protected computer;" (C) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than 20 years, or both, in the case of—"
https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
[2] http://motherboard.vice.com/blog/facebook-is-refusing-to-pay...
It isn't a trick...Some of the approved domains have no IP addresses directly associated with them. You have to traverse a reference to another domain name, not on the list, to get to an actual IP address.
Now if that traversal is by something called a CNAME or something called an MX, does it matter?
Edit: just saw this post was from September. Author probably made thousands in rewards circulating this vulnerability.
Source: I am a member of said community: https://bugcrowd.com/bored-engineer, https://hackerone.com/bored-engineer, etc
I have no idea if they fixed this and they gave me a t-shirt.
(I used to help maintain the system responsible for this, but don't work there anymore.)
edit: here's what we sent to heroku https://gist.github.com/bdittmer/6461b7a5093acd7d6263
I had same experience with Salesforce
>Also at the moment of writing this bug, it has come to my attention that SendGrid has added extra verification which forces you to have a verified domain before adding a inbound parse webhook.
[1] http://blog.pentestnepal.tech/post/150381068912/how-i-snoope...
[2] http://mxtoolbox.com/SuperTool.aspx?action=mx%3aslack.com&ru...
A bug bounty incentivizes people to look for bugs. But when you find an interesting bug like this you have the option of either having the possibility of making millions from the social engineering possibilities alone, or claiming the bug bounty and get $10k. Of course claiming the bounty is the moral thing to do, but some people with both the skill and motivation to do bug bounties are bound to have lower moral standards.
There isn't really a market for most XSS, CSRF or even RCEs bugs for web properties. Getting the bounty payout for a bug from the owner is often the best deal available. I think the only exception to the no-market situation is browser RCEs and smart phone OS jailbreaks.
This vulnerability only allows you to intercept future incoming emails that are delivered to sendgrid domains. Even if it did allow access to all of their customers internal emails there aren't many buyers (and no obvious marketplaces) out there for that kind of access.
The risk is simply too high, if you're Lyft (for example) being caught with that access (even if it was never used) would be a possible terminal event for the company. Purchasers would be buying a giant liability and a small competitive advantage.
Maybe there are shady companies or criminal groups who would be interested in the access but even then I feel $10k would be roughly how much money they'd be willing to spend (considering the same amount of money could also buy thousands of verified credit cards or a million email addresses at legitimate providers).
The "grey market" prices I've seen (~5 years ago now) from independent researchers, small firms specializing in vulndev for law enforcement / intelligence and the bigger famous security firms go something like this ("black market" criminal markets are similar I hear but I have no first hand knowledge there):
250k would get you a iOS jailbreak (for a recent iOS version)
100k would get you an IE/Firefox/Chrome zero day (though not with a sanbox escape, you'd have to pay separately for a privesc)
~25k for a Linux privesc
For an RCEs in medium popularity services (databases, ftp servers, etc) you'd be looking at something like 10k (or often thrown in free with a bigger purchase or support contract as a good will gesture).
The prices would also change based on the quality of the exploit, how recent the version the exploit targeted was, the amount of exclusivity you want (more for full exclusivity) and whether the research was specially commissioned (if you had asked a firm to look into a specific piece of software the price would be higher). The larger providers also encouraged organizations to sign subscription deals and longer term service contracts that could include free exploits or reduced costs.
That said, there's a lot of information asymmetry in the market so I'd expect a lot of variance in prices.
So, on the balance, you are increasing motivation for people who are not willing to harm for cash while leaving the motivation of the willing unchanged. I would be tempted to argue that it is flat out unwise to NOT run a bug bounty program, although it would be much smarter to offer larger bounties. I could make an argument for bounties exceeding the projected amount the vulnerability would be worth on the black market, I think, but that's a different subject.
The black market is very unlikely to be a place you could sell a bug in a specific
website or service. It is not “worth millions”. Please stop repeating this.
[0] - https://medium.com/@collingreene/to-the-bounty-hunters-9259b...Nobody said it was "worth millions" but I have second-degree connections in Scandinavia that would pay 10x, like I said ($100,000).
@collingreene doesn't sound too familiar with these rather-illicit organizations, he strikes me as a product manager type person with a loud voice, not someone who actually has found and sold zero-days before. Maybe he doesn't have the technical acumen to do so, but hey, I'm not one to judge.
It's hard to establish proof that the market value on the black market is, in fact, much higher given that it is the black market (you're not going to find these people on Medium); However, one public example of this is the leaked Stuxnet details showing similarly high 5-digit prices for zero-days.
This isn't a specific bug either (it wasn't "oh, the log files for that one UberEATS micro-service were visible"), this flaw allows you to intercept the emails of pretty much any single one of SendGrid's clients. Imagine the damage someone could do with that, had it gotten into the wrong hands. Only $10k, what an insult.
EDIT: Upon further examination, it turns out that said author also contradicts himself and corroborates my own argument:
https://medium.com/@collingreene/why-product-security-is-har...
Primary source: https://www.wired.com/2016/09/top-shelf-iphone-hack-now-goes...
https://www.united.com/web/en-US/content/Contact/bugbounty.a...
Don't these companies get that researchers need to live?!