|
|
|
|
|
by js2
10 days ago
|
|
So what I'm trying to clarify here is whether this worked when the final address was an icloud.com address. i.e. there are two scenarios: 1. hello_world_0a@icloud.com -> real@icloud.com 2. hello_world_0a@icloud.com -> real@example.com where example.com is not any of icloud.com, me.com, mac.com (such as in your example, gmail.com) HME can be configured for either of setups. I really want to establish whether you were able to unmask a real address under (1), since in this case any bounce message should occur too early to disclose the real address. Under (2), the bounce message can occur after rewriting and I can totally see how it was leaking the real address. (For the purposes of the exploit, it doesn't matter that you used Mailgun to send the email, but I appreciate that detail.) |
|
Even in case (1), isn't it possible that Hide My Email bounces happen differently from regular @icloud.com bounces despite being on the same domain?
We've also been wondering whether Hide My Email was ever responsible for generating the messages with meant-to-be-hidden addresses or whether it was only passing them along and failing to hide them. I don't think we have enough information to tell.