Live data from Hacker News

How I hacked hundreds of companies through their helpdesk (2017)

medium.com

1–10 of 20 posts

Re: How I hacked hundreds of companies through their helpdesk (2017)

#4
post #3

E-mails sent to support@company.com sometimes turned up in an online support portal such as Zendesk, Kayako, (Fresh)Desk, WHMCS or a custom tool. I don't understand how the author is able to read email sent to support@company.com?

Support emails sent to Zendesk/etc allow a user to see the originating support email as well as the company's response to that email via their online support interface.

Re: How I hacked hundreds of companies through their helpdesk (2017)

#5
post #3

E-mails sent to support@company.com sometimes turned up in an online support portal such as Zendesk, Kayako, (Fresh)Desk, WHMCS or a custom tool. I don't understand how the author is able to read email sent to support@company.com?

This confused me initially. Basically, he signs up to Company (not Slack) as noreply@slack.com. Then he creates an account at Slack as support@company.com. Slack sends an email FROM noreply@slack.com to support@company.com. The email gets taken by the helpdesk and detects there is a user called 'noreply@slack.com'. Although this email was not verified, the ticket becomes viewable in the helpdesk.

Re: How I hacked hundreds of companies through their helpdesk (2017)

#6
post #5
post #3

E-mails sent to support@company.com sometimes turned up in an online support portal such as Zendesk, Kayako, (Fresh)Desk, WHMCS or a custom tool. I don't understand how the author is able to read email sent to support@company.com?

This confused me initially. Basically, he signs up to Company (not Slack) as noreply@slack.com. Then he creates an account at Slack as support@company.com. Slack sends an email FROM noreply@slack.com to support@company.com. The email gets taken by the helpdesk and detects there is a user called 'noreply@slack.com'. Although this email was not verified, the ticket becomes viewable in the helpdesk.

And, as I understood it, he was able to read arbitrary emails sent to support@ by getting access to their ticketing system instances just like he got access to Slack.

He doesn't say so explicitly, but presumably he did the same thing with ZenDesk as he did with Slack - he signed up for ZenDesk with support@target-company.com and then the target company's service with, say, no-reply@zendesk.com. And then once he had access to their ZenDesk instance he could read all emails sent to support@target-company.com, which opened up all kinds of doors.

Re: How I hacked hundreds of companies through their helpdesk (2017)

#10
post #9

I look at all the energy going into ridiculous password requirements and super esoterica attach vectors and of course the real compromises are in plain sight.

This is what bothers me about stupid password requirements that create massive user friction because we'll never remember the password. Passwords aren't guessed or brute forced 99% of the time. They are stolen or phished or access is gained in another manner.
Post reply on HN