Closed Bug 1286192 Opened 9 years ago Closed 9 years ago

No SPF record on getfirefox.com and browserid.org

Categories

(Infrastructure & Operations :: Infrastructure: Mail, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: takashi.kazenomamani, Unassigned)

References

()

Details

(Keywords: reporter-external, sec-low, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

I had checked SPF record on newly added eligible domains. These two domains are missing SPF record. getfirefox.com browserid.org
Flags: sec-bounty?
off-topic comment I checked whether my report is duplicate. "mozilla.org" and "firefox.com" are reported in the past, but I believe "getfirefox.com" and "browserid.org" have not been reported yet. If this is a duplicate issue, I am really sorry. It's not clear to me that these domain's SPF are important for your team. Another company paid bounty to a researcher even if no email was sent from reported domain. source: https://hackerone.com/reports/92740 I have no way to evaluate this, but I reported to your team because I believe this is "Missing Additional Security Controls(sec-moderate)."
It's more of a mail infrastructure issue than a website bug. We have hundreds of domains, and while this hasn't really been a problem in the (4 and 11 years) that these domains have been around respectively, it's still probably best practice to get SPF records on them, if we're not sending mail from them. > v=spf1 -all
Assignee: nobody → infra
Group: websites-security → mozilla-employee-confidential
Component: Other → Infrastructure: Mail
Keywords: sec-low
Product: Websites → Infrastructure & Operations
QA Contact: limed
I can agree on adding: > v=spf1 -all To non email delivery / sending domains. I've added the rule for getfirefox.com however I don't control browserid.org so I can't change the DNS entries for that particular domain.
CC'ed appropriate person for browserid.org
Missing anti-spam protections are not eligible for a bug bounty
Flags: sec-bounty? → sec-bounty-
Nothing else on my part here
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Group: mozilla-employee-confidential
You need to log in before you can comment on or make changes to this bug.