Closed
Bug 1286192
Opened 9 years ago
Closed 9 years ago
No SPF record on getfirefox.com and browserid.org
Categories
(Infrastructure & Operations :: Infrastructure: Mail, task)
Infrastructure & Operations
Infrastructure: Mail
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: takashi.kazenomamani, Unassigned)
References
()
Details
(Keywords: reporter-external, sec-low, Whiteboard: [reporter-external] [web-bounty-form] [verif?])
I had checked SPF record on newly added eligible domains.
These two domains are missing SPF record.
getfirefox.com
browserid.org
Flags: sec-bounty?
off-topic comment
I checked whether my report is duplicate. "mozilla.org" and "firefox.com" are reported in the past, but I believe "getfirefox.com" and "browserid.org" have not been reported yet. If this is a duplicate issue, I am really sorry.
It's not clear to me that these domain's SPF are important for your team.
Another company paid bounty to a researcher even if no email was sent from reported domain.
source: https://hackerone.com/reports/92740
I have no way to evaluate this, but I reported to your team because I believe this is "Missing Additional Security Controls(sec-moderate)."
Comment 2•9 years ago
|
||
It's more of a mail infrastructure issue than a website bug. We have hundreds of domains, and while this hasn't really been a problem in the (4 and 11 years) that these domains have been around respectively, it's still probably best practice to get SPF records on them, if we're not sending mail from them.
> v=spf1 -all
Assignee: nobody → infra
Group: websites-security → mozilla-employee-confidential
Component: Other → Infrastructure: Mail
Keywords: sec-low
Product: Websites → Infrastructure & Operations
QA Contact: limed
Comment 3•9 years ago
|
||
I can agree on adding:
> v=spf1 -all
To non email delivery / sending domains.
I've added the rule for getfirefox.com however I don't control browserid.org so I can't change the DNS entries for that particular domain.
Comment 4•9 years ago
|
||
CC'ed appropriate person for browserid.org
Comment 5•9 years ago
|
||
Missing anti-spam protections are not eligible for a bug bounty
Flags: sec-bounty? → sec-bounty-
Comment 6•9 years ago
|
||
Nothing else on my part here
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Updated•1 year ago
|
Group: mozilla-employee-confidential
Updated•1 year ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•