Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure I would have contacted Apple about this, given their penchant for punishing security researchers who bring problems to their attention.

What I don't fully understand is if the attacker doesn't need access to the email account in question, why would they even use valid email addresses? Wouldn't it be less risky to use bogus addresses?



It's because most registration form not only checks that the email address you entered is valid but also whether it exists. This is done by using nslookup to query for a domain's MX record and then checking the specific address.

Here's a post I found detailing how to use it: http://www.webdigi.co.uk/blog/2009/how-to-check-if-an-email-...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: