Account email vulnerability
Reported by Nathaniel Bibler | October 2nd, 2008 @ 07:40 AM
The system appears to currently give the list of all valid email addresses in the account when an email is sent to create a new ticket for a project which is not from a known email address.
For example, if I send an email from badguy@foo.domain to a valid project address, the Professor (email system) replies with:
We received an email from this address that had problems being processed into a new Lighthouse ticket:
Failed for "badguy@foo.domain" to : Invalid token: ["goodaddress1@domain.url", "goodaddress2@domain.url", ...]:
TROUBLESHOOT http://lighthouseapp.com/help/ho...
FILE BUG http://activereload.lighthouseap...
It would then seem to be a trivial task for a spammer to actually spoof a valid address and successfully spam projects, among other devious things. Which is exactly what that feature was in place to avoid.
Comments and changes to this ticket
-
Nathaniel Bibler October 2nd, 2008 @ 09:12 AM
It could possibly be that the email was 'redirected' through Apple Mail.. looking back at it, the redirected message contains both 'To' and 'Resent-To' headers. The Resent-To appears to be the valid Lighthouse address, and To matches those email addresses sent back to me.
I'll chalk this one up to user error and silly Apple Mail redirection.
-
rick October 2nd, 2008 @ 02:11 PM
- → Tag changed from bug email security spam to bug email spam
It's showing the emails because it's looking for the lighthouse address in the
Toheader. It's not listing anything you didn't already have in the email headers. Though, there should be a better way to parse out the lighthouse token. I've been working on this stuff lately and want to upgradethe professorreally soon. -
Will October 27th, 2008 @ 10:21 AM
- → State changed from new to open
- → Assigned user changed from to rick
Please Login or create a free account to add a new comment.
You can update this ticket by sending an email to from your email client. (help)
Create your profile
Help contribute to this project by taking a few moments to create your personal profile. Create your profile »
Using Lighthouse to track Lighthouse.
