Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

11–20 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#11
A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!".

Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision.

Edit: Another user here has pointed out the reasoning

> It's owned by private equity. Slowly cutting costs and bleeding the brand dry

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#14
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

If the bounty is big enough you basically need to retain a lawyer so the whole thing is done right and prevent being scammed.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#15
Years ago I had a similar train of thought: Zendesk is used by a ton of companies for their support site, and back then HTTPOnly cookies and javascript site isolation were much less of a thing. I found an XSS bug on Zendesk, which also translates into XSS on any site that used it as `support.fortune500.com` subdomain (which was a lot). You could then use it to exploit the main site, either by leaking user cookies or reading CSRF tokens from page contents because it was a subdomain.

Zendesk gave me a tshirt but not any money for it. C'est la vie.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#16
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

That is why a black market exists for this stuff.

The black market also exists because the potential payout for serious 0days by official programs is almost always less than what a third-party adversary will pay (if the target(s) for them are worth it).

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#20
Another example of how weasley Zendesk can be:

They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk.

http://zendeskalternative.com/

While not illegal, it shows the way they think, a sort of manipulative pettiness.

Post reply on HN