SpamChannel icon indicating copy to clipboard operation
SpamChannel copied to clipboard

CF Abuse no longer possible as of today (14 Aug 23) ?

Open P4l1ndr0m opened this issue 1 year ago • 2 comments

Hello byt3bl33d3r. What an awesome research and great presentation ! Thank you for sharing.

Just a quick question, is this technique still viable today using CF workers ? Asking because the doc for Domain Lockdown Record, now states : "Note that participation in Domain Lockdown is now mandatory for Cloudflare Workers users."

This would imply that only authorized Cloudflare accounts would be able to abuse the technique you documented ? Is that a valid assumption ? Thank you in advance, and looking forward to more amazing research from you.

P4l1ndr0m avatar Aug 13 '23 16:08 P4l1ndr0m

it does indeed look like they silently made it mandatory to have the domain lockdown record now so spoofing emails through CF workers is no longer possible. However you can still spoof emails by just signing up to Mailchannels through their website (80$) and use their normal SMTP relay.

Will update the README accordingly.

byt3bl33d3r avatar Aug 13 '23 18:08 byt3bl33d3r

Could you provide an example how is it possible to spoof emails through their "normal" SMTP relay ? As far as i understand the Domain lockdown prevents it in any form, since as a domain owner i would insert txt record with my own authid which you (as a 'spoofer') do not have access to.

dvnscr avatar Jul 09 '24 11:07 dvnscr